
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24460 affects JetBrains TeamCity versions before 2024.12.1. The vulnerability is related to improper access control that allowed unauthorized users to see Projects' names in the agent pool (JetBrains Security, NVD Database).
The vulnerability is classified as a medium severity issue with a CVSS v3.1 score of 4.3, indicating a relatively moderate risk level. It is categorized under CWE-863 (Incorrect Authorization) which relates to improper implementation of access controls (Rapid7 Database).
The vulnerability allows unauthorized users to view project names within the agent pool, potentially exposing sensitive information about the organization's project structure and naming conventions (JetBrains Security).
The vulnerability has been fixed in TeamCity version 2024.12.1. Organizations using affected versions should upgrade to this version or later to mitigate the security risk (JetBrains Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."