JetBrains TeamCity Cross-Site Request Forgery Vulnerability in OAuth Login Integration

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in JetBrains TeamCity versions prior to 2025.07. This issue arises in the external OAuth login integration, allowing attackers to potentially exploit the CSRF vulnerability during the authentication process.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, potentially allowing attackers to manipulate user accounts or access sensitive information.

Remediation

Users can upgrade to JetBrains TeamCity version 2025.07 or later to address this vulnerability.

Added: Jul 28, 2025, 5:44 PM
Updated: Jul 28, 2025, 5:44 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.