CVE-2019-15848: JetBrains TeamCity

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

Affected products

  • JetBrains TeamCity: version 2019.1 only; version 2019.1.1 only

Published 2019-09-05. Last modified 2026-06-17.