Inclusion of Sensitive Information in Log Files in TeamCity - CVE-2025-46432
Published: April 25, 2025 / Updated: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in build logs when logging base64-encoded credentials. A remote user can access build logs containing exposed credentials to disclose sensitive information.