Inclusion of Sensitive Information in Log Files in TeamCity - CVE-2025-31139
Published: March 27, 2025 / Updated: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in build log when viewing or accessing build logs containing a base64 encoded password. A remote user can access a build log containing a base64 encoded password to disclose sensitive information.