Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:jetbrains:teamcity:9.1.4:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2024-56355 |
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS Published: December 20, 2024; 10:15:09 AM -0500 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-56354 |
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission Published: December 20, 2024; 10:15:09 AM -0500 |
V4.0:(not available) V3.1: 4.9 MEDIUM V2.0:(not available) |
CVE-2024-56353 |
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies Published: December 20, 2024; 10:15:09 AM -0500 |
V4.0:(not available) V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2024-56352 |
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page Published: December 20, 2024; 10:15:08 AM -0500 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-56351 |
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles Published: December 20, 2024; 10:15:08 AM -0500 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2024-56350 |
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects Published: December 20, 2024; 10:15:08 AM -0500 |
V4.0:(not available) V3.1: 4.3 MEDIUM V2.0:(not available) |
CVE-2024-56349 |
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs Published: December 20, 2024; 10:15:08 AM -0500 |
V4.0:(not available) V3.1: 5.3 MEDIUM V2.0:(not available) |
CVE-2024-56348 |
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents Published: December 20, 2024; 10:15:05 AM -0500 |
V4.0:(not available) V3.1: 4.3 MEDIUM V2.0:(not available) |
CVE-2024-47951 |
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings Published: October 08, 2024; 12:15:13 PM -0400 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-47950 |
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings Published: October 08, 2024; 12:15:12 PM -0400 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-47949 |
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location Published: October 08, 2024; 12:15:12 PM -0400 |
V4.0:(not available) V3.1: 7.5 HIGH V2.0:(not available) |
CVE-2024-47948 |
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups Published: October 08, 2024; 12:15:12 PM -0400 |
V4.0:(not available) V3.1: 7.5 HIGH V2.0:(not available) |
CVE-2024-47161 |
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API Published: October 08, 2024; 12:15:12 PM -0400 |
V4.0:(not available) V3.1: 6.5 MEDIUM V2.0:(not available) |
CVE-2024-43810 |
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin Published: August 16, 2024; 11:15:29 AM -0400 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-43809 |
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page Published: August 16, 2024; 11:15:29 AM -0400 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2024-43808 |
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin Published: August 16, 2024; 11:15:29 AM -0400 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-43807 |
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page Published: August 16, 2024; 11:15:29 AM -0400 |
V4.0:(not available) V3.1: 5.4 MEDIUM V2.0:(not available) |
CVE-2024-43114 |
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions Published: August 06, 2024; 9:15:56 AM -0400 |
V4.0:(not available) V3.1: 7.8 HIGH V2.0:(not available) |
CVE-2024-41829 |
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection Published: July 22, 2024; 11:15:05 AM -0400 |
V4.0:(not available) V3.1: 7.5 HIGH V2.0:(not available) |
CVE-2024-41828 |
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time Published: July 22, 2024; 11:15:05 AM -0400 |
V4.0:(not available) V3.1: 6.5 MEDIUM V2.0:(not available) |