Open Redirect Vulnerability in JetBrains TeamCity
CVE-2025-47854

6.1MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
20 May 2025

What is CVE-2025-47854?

An open redirect vulnerability has been identified in JetBrains TeamCity, where improper validation on the editing VCS Root page could allow unauthorized redirection of users to external sites. This could potentially be exploited by attackers to lead users to phishing sites or other malicious links, compromising the security of the system. Version 2025.03.2 and later have addressed this issue, making it essential for users to update to the latest version to safeguard against such vulnerabilities.

Affected Version(s)

TeamCity 0 < 2025.03.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47854 : Open Redirect Vulnerability in JetBrains TeamCity