CVE-2015-1313: JetBrains TeamCity

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.

Affected products

  • JetBrains TeamCity: from 8.0, before 9.0.2 (fixed in 9.0.2)

Published 2023-06-29. Last modified 2026-06-17.