CVE-2025-24461
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 862
Summary
CVE-2025-24461 is a newly disclosed vulnerability in JetBrains TeamCity. Before version 2024.12.1, this software failed to adequately restrict access to the Test Connection endpoint, enabling unauthorized users to decrypt connection secrets without proper permissions. This issue poses a significant risk to sensitive data, as it bypasses essential security measures. TeamCity users are urged to update to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- TeamCity
Affected Vendors
- JetBrains