JetBrains TeamCity Improper Access Control Vulnerability Allowing Build Settings Disclosure

Vulnerability

A vulnerability in JetBrains TeamCity prior to version 2025.07 allows improper access control, which can lead to the unauthorized disclosure of build settings through snapshot dependencies. This issue could be exploited by users with certain permissions to access sensitive build configuration information that should be restricted.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive build configuration details, potentially leading to further security implications depending on the nature of the disclosed information.

Remediation

Users can upgrade to JetBrains TeamCity version 2025.07 or later to address this vulnerability.

Added: Jul 28, 2025, 5:35 PM
Updated: Jul 28, 2025, 5:35 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.