2025.11.5 unauthenticated SSRF via build status was possible
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Tue, 02 Jun 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:* |
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SSRF via Build Status in JetBrains TeamCity |
Fri, 29 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jetbrains
Jetbrains teamcity |
|
| Vendors & Products |
Jetbrains
Jetbrains teamcity |
Fri, 29 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-05-29T19:30:12.967Z
Reserved: 2026-05-29T18:07:55.363Z
Link: CVE-2026-49372
Updated: 2026-05-29T19:30:08.411Z
Status : Analyzed
Published: 2026-05-29T19:16:27.030
Modified: 2026-06-02T04:07:42.343
Link: CVE-2026-49372
No data.
OpenCVE Enrichment
Updated: 2026-05-29T19:45:06Z