CSRF Vulnerability in JetBrains TeamCity by JetBrains
CVE-2025-54529

3.7LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
28 July 2025

What is CVE-2025-54529?

A Cross-Site Request Forgery (CSRF) vulnerability was identified in JetBrains TeamCity prior to version 2025.07. This security issue permits attackers to exploit the external OAuth login integration, potentially allowing unauthorized actions on behalf of authenticated users. Proper measures should be taken to mitigate this vulnerability to ensure secure operations within the software.

Affected Version(s)

TeamCity 0 < 2025.07

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54529 : CSRF Vulnerability in JetBrains TeamCity by JetBrains