CVEs (273)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page |
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration |
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies |
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows |
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions |
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration |
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow |
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible |
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions |
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible |
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible |
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible |
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page |
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible |
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab |
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible |
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs |
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page |