
Cloud Vulnerability DB
A community-led vulnerabilities database
In JetBrains TeamCity before version 2025.03.3, a security vulnerability was identified where usernames were exposed to users without proper permissions. The vulnerability was disclosed on June 23, 2025, and was assigned CVE-2025-52878. This security issue was classified as a Missing Authorization vulnerability (CWE-862) (NVD, Wiz).
The vulnerability has been assigned a CVSS v3.1 Base Score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. This scoring indicates that the vulnerability requires network access and low privileges to exploit, with no user interaction needed. The attack results in low confidentiality impact without affecting integrity or availability (NVD).
The primary security impact of this vulnerability is the unauthorized disclosure of usernames to users who do not have the appropriate permissions within the TeamCity environment. This information disclosure could potentially compromise user privacy and lead to unauthorized access to user information (Wiz).
The vulnerability has been addressed in TeamCity version 2025.03.3. Organizations using affected versions should upgrade to version 2025.03.3 or later to remediate this security issue (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."