← Back

Teamcity

teamcity

Vendor: Jetbrains • 269 CVEs

CVEs (269)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Jun 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the...Show more
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.Show less
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
1Jetbrains
1Teamcity
Nov 21, 2024
May 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible