CVE-2025-24461: Medium severity jetbrains teamcity vulnerability
Published Jan 21, 2025
·Updated
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
Affected Software
2 affected components
JetBrains TeamCity<2024.12.1
JetBrains TeamCity=2024.12.1
Event History
Jan 21, 2025
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Nov 29, 57087
Event
via FIRST·02:18 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-24461?
CVE-2025-24461 has a medium severity rating due to the potential unauthorized access to sensitive connection secrets.
2
How do I fix CVE-2025-24461?
To fix CVE-2025-24461, update JetBrains TeamCity to version 2024.12.1 or later.
3
What are the implications of CVE-2025-24461?
The implications of CVE-2025-24461 include the risk of sensitive connection secrets being decrypted without proper permissions.
4
Which versions of JetBrains TeamCity are affected by CVE-2025-24461?
CVE-2025-24461 affects all versions of JetBrains TeamCity prior to 2024.12.1.
5
Is there a workaround for CVE-2025-24461?
There is no documented workaround for CVE-2025-24461 other than upgrading to the patched version.