JetBrains TeamCity 2023.05

CPE Details

JetBrains TeamCity 2023.05
2023.05
2023-06-02
11h12 +00:00
2023-07-06
14h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jetbrains:teamcity:2023.05:*:*:*:*:*:*:*

Informations

Vendor

jetbrains

Product

teamcity

Version

2023.05

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-24460 2025-01-21
17h23 +00:00
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
4.3
Medium
CVE-2025-24459 2025-01-21
17h23 +00:00
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
6.1
Medium
CVE-2024-56356 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
7.1
High
CVE-2024-56355 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
5.4
Medium
CVE-2024-56354 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
5.5
Medium
CVE-2024-56353 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
6.5
Medium
CVE-2024-56352 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
5.4
Medium
CVE-2024-56351 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
8.8
High
CVE-2024-56350 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
4.3
Medium
CVE-2024-56349 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
5.3
Medium
CVE-2024-56348 2024-12-20
14h11 +00:00
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
4.3
Medium
CVE-2024-47951 2024-10-08
15h48 +00:00
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
5.4
Medium
CVE-2024-47950 2024-10-08
15h48 +00:00
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
5.4
Medium
CVE-2024-47949 2024-10-08
15h48 +00:00
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
7.5
High
CVE-2024-47948 2024-10-08
15h48 +00:00
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
7.5
High
CVE-2024-47161 2024-10-08
15h48 +00:00
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
6.5
Medium
CVE-2024-43810 2024-08-16
14h51 +00:00
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
5.4
Medium
CVE-2024-43809 2024-08-16
14h51 +00:00
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
6.1
Medium
CVE-2024-43808 2024-08-16
14h51 +00:00
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
5.4
Medium
CVE-2024-43807 2024-08-16
14h51 +00:00
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
5.4
Medium
CVE-2024-43114 2024-08-06
12h48 +00:00
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
7.8
High
CVE-2024-41829 2024-07-22
14h50 +00:00
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
7.5
High
CVE-2024-41828 2024-07-22
14h50 +00:00
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
6.5
Medium
CVE-2024-41827 2024-07-22
14h50 +00:00
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
9.8
Critical
CVE-2024-41826 2024-07-22
14h50 +00:00
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
4.8
Medium
CVE-2024-41825 2024-07-22
14h50 +00:00
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
5.4
Medium
CVE-2024-41824 2024-07-22
14h50 +00:00
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
6.5
Medium
CVE-2024-39879 2024-07-01
17h07 +00:00
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
5.3
Medium
CVE-2024-39878 2024-07-01
17h07 +00:00
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
5.3
Medium
CVE-2024-36470 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
9.8
Critical
CVE-2024-36378 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
7.5
High
CVE-2024-36377 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
8.1
High
CVE-2024-36376 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
8.1
High
CVE-2024-36375 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
5.3
Medium
CVE-2024-36374 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
5.4
Medium
CVE-2024-36373 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
5.4
Medium
CVE-2024-36372 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
6.1
Medium
CVE-2024-36371 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
5.4
Medium
CVE-2024-36370 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
5.4
Medium
CVE-2024-36369 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
5.4
Medium
CVE-2024-36368 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
5.4
Medium
CVE-2024-36367 2024-05-29
13h29 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
6.1
Medium
CVE-2024-36366 2024-05-29
13h28 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
6.1
Medium
CVE-2024-36365 2024-05-29
13h28 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
8.1
High
CVE-2024-36364 2024-05-29
13h28 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
6.5
Medium
CVE-2024-36363 2024-05-29
13h28 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
5.4
Medium
CVE-2024-36362 2024-05-29
13h28 +00:00
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
6.5
Medium
CVE-2024-35302 2024-05-16
10h32 +00:00
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
6.1
Medium
CVE-2024-35301 2024-05-16
10h32 +00:00
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
5.5
Medium
CVE-2024-31140 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
4.9
Medium
CVE-2024-31139 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
8.1
High
CVE-2024-31138 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
5.4
Medium
CVE-2024-31137 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
6.8
Medium
CVE-2024-31136 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
7.4
High
CVE-2024-31135 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
6.1
Medium
CVE-2024-31134 2024-03-28
15h07 +00:00
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
6.5
Medium
CVE-2024-29880 2024-03-21
13h56 +00:00
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
7.8
High
CVE-2024-28174 2024-03-06
16h52 +00:00
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
5.8
Medium
CVE-2024-27199 2024-03-04
17h21 +00:00
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
7.3
High
CVE-2024-27198 2024-03-04
17h21 +00:00
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
9.8
Critical
CVE-2024-23917 2024-02-06
09h21 +00:00
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
9.8
Critical
CVE-2024-24942 2024-02-06
09h21 +00:00
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
5.3
Medium
CVE-2024-24938 2024-02-06
09h21 +00:00
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
5.3
Medium
CVE-2024-24937 2024-02-06
09h21 +00:00
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
5.4
Medium
CVE-2024-24936 2024-02-06
09h21 +00:00
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
5.3
Medium
CVE-2023-50870 2023-12-15
13h48 +00:00
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
8.8
High
CVE-2023-43566 2023-09-19
16h57 +00:00
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
5.4
Medium
CVE-2023-42793 2023-09-19
16h57 +00:00
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
9.8
Critical
CVE-2023-41250 2023-08-25
12h58 +00:00
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
6.1
Medium
CVE-2023-41249 2023-08-25
12h58 +00:00
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
6.1
Medium
CVE-2023-41248 2023-08-25
12h58 +00:00
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
5.4
Medium
CVE-2023-39175 2023-07-25
14h45 +00:00
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
6.1
Medium
CVE-2023-39174 2023-07-25
14h45 +00:00
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers
7.5
High
CVE-2023-39173 2023-07-25
14h45 +00:00
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
8.8
High
CVE-2023-38067 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
6.5
Medium
CVE-2023-38066 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads
6.1
Medium
CVE-2023-38065 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible
5.4
Medium
CVE-2023-38064 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
6.5
Medium
CVE-2023-38063 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible
5.4
Medium
CVE-2023-38062 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
6.5
Medium
CVE-2023-38061 2023-07-12
12h48 +00:00
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
5.4
Medium