CVE-2019-12157: JetBrains TeamCity

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.

Affected products

  • JetBrains TeamCity: before 2018.2.5 (fixed in 2018.2.5)
  • JetBrains Upsource: up to and including 2018.2; version 2018.2 only

Published 2019-10-02. Last modified 2026-06-17.