CVE-2025-24460: Medium severity jetbrains teamcity vulnerability
Published Jan 21, 2025
·Updated
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Affected Software
2 affected components
JetBrains TeamCity<2024.12.1
JetBrains TeamCity<2024.12.1
Event History
Jan 21, 2025
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Nov 29, 57087
Event
via FIRST·02:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-24460?
CVE-2025-24460 is classified as a high severity vulnerability due to improper access control in JetBrains TeamCity.
2
How do I fix CVE-2025-24460?
To fix CVE-2025-24460, upgrade JetBrains TeamCity to version 2024.12.1 or later.
3
What does CVE-2025-24460 affect?
CVE-2025-24460 affects JetBrains TeamCity versions prior to 2024.12.1.
4
What is the impact of CVE-2025-24460?
CVE-2025-24460 allows unauthorized users to see project names in the agent pool.
5
Is CVE-2025-24460 straightforward to exploit?
Yes, CVE-2025-24460 can be exploited easily due to its improper access control mechanism.