Filtered by vendor Jetbrains Subscriptions
Filtered by product Teamcity Subscriptions
Total 209 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-34221 1 Jetbrains 1 Teamcity 2025-01-09 4.6 Medium
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
CVE-2023-34222 1 Jetbrains 1 Teamcity 2025-01-09 4.6 Medium
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
CVE-2023-34223 1 Jetbrains 1 Teamcity 2025-01-09 4.3 Medium
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
CVE-2023-34224 1 Jetbrains 1 Teamcity 2025-01-09 4.8 Medium
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
CVE-2023-34225 1 Jetbrains 1 Teamcity 2025-01-09 4.6 Medium
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
CVE-2023-34226 1 Jetbrains 1 Teamcity 2025-01-09 4.6 Medium
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
CVE-2023-34227 1 Jetbrains 1 Teamcity 2025-01-09 5.3 Medium
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
CVE-2023-34228 1 Jetbrains 1 Teamcity 2025-01-09 5.3 Medium
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
CVE-2023-34229 1 Jetbrains 1 Teamcity 2025-01-09 4.6 Medium
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
CVE-2023-34220 1 Jetbrains 1 Teamcity 2025-01-09 4.6 Medium
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2024-56348 1 Jetbrains 1 Teamcity 2025-01-02 4.3 Medium
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
CVE-2024-56349 1 Jetbrains 1 Teamcity 2025-01-02 5.3 Medium
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2024-56350 1 Jetbrains 1 Teamcity 2025-01-02 4.3 Medium
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
CVE-2024-56351 1 Jetbrains 1 Teamcity 2025-01-02 6.3 Medium
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
CVE-2024-56352 1 Jetbrains 1 Teamcity 2025-01-02 4.6 Medium
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
CVE-2024-56353 1 Jetbrains 1 Teamcity 2025-01-02 5.5 Medium
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-56354 1 Jetbrains 1 Teamcity 2025-01-02 5.5 Medium
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
CVE-2024-56355 1 Jetbrains 1 Teamcity 2025-01-02 4.6 Medium
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
CVE-2024-56356 1 Jetbrains 1 Teamcity 2025-01-02 5.9 Medium
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-31140 1 Jetbrains 1 Teamcity 2024-12-16 4.1 Medium
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools