← Back

Teamcity

teamcity

Vendor: Jetbrains • 269 CVEs

CVEs (269)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 16, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
1Jetbrains
1Teamcity
Dec 16, 2024
May 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 6, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly