CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
17h23 +00:00 |
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool | 4.3 |
Medium |
|
17h23 +00:00 |
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page | 6.1 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | 7.1 |
High |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS | 5.4 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | 5.5 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies | 6.5 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page | 5.4 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | 8.8 |
High |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | 4.3 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | 5.3 |
Medium |
|
14h11 +00:00 |
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | 4.3 |
Medium |
|
15h48 +00:00 |
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | 5.4 |
Medium |
|
15h48 +00:00 |
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | 5.4 |
Medium |
|
15h48 +00:00 |
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | 7.5 |
High |
|
15h48 +00:00 |
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | 7.5 |
High |
|
15h48 +00:00 |
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API | 6.5 |
Medium |