VYPR

by Jetbrains

Source repositories

CVEs (166)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-478520.000.00May 20, 2025In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
CVE-2025-478510.000.00May 20, 2025In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
CVE-2025-466180.000.00Apr 25, 2025In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
CVE-2025-464330.000.00Apr 25, 2025In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
CVE-2025-464320.000.00Apr 25, 2025In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
CVE-2025-311410.000.00Mar 27, 2025In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
CVE-2025-311390.000.00Mar 27, 2025In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
CVE-2025-264920.000.00Feb 11, 2025In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
CVE-2025-244610.000.00Jan 21, 2025In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
CVE-2025-244600.000.00Jan 21, 2025In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
CVE-2024-563560.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
CVE-2024-563540.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
CVE-2024-563530.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
CVE-2024-563510.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
CVE-2024-563500.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
CVE-2024-563490.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
CVE-2024-563480.000.00Dec 20, 2024In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
CVE-2024-479510.000.00Oct 8, 2024In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
CVE-2024-479500.000.00Oct 8, 2024In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
CVE-2024-479490.000.01Oct 8, 2024In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Page 4 of 9