VYPR

Teamcity

by Jetbrains

Source repositories

CVEs (166)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2024-479480.000.00Oct 8, 2024In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
CVE-2024-471610.000.00Oct 8, 2024In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
CVE-2024-438090.000.01Aug 16, 2024In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
CVE-2024-438080.000.05Aug 16, 2024In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
CVE-2024-431140.000.00Aug 6, 2024In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
CVE-2024-418290.000.00Jul 22, 2024In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
CVE-2024-418280.000.00Jul 22, 2024In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
CVE-2024-418270.000.00Jul 22, 2024In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
CVE-2024-418260.000.01Jul 22, 2024In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
CVE-2024-418240.000.00Jul 22, 2024In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
CVE-2024-398790.000.00Jul 1, 2024In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
CVE-2024-398780.000.00Jul 1, 2024In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
CVE-2024-364700.000.00May 29, 2024In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
CVE-2024-363780.000.00May 29, 2024In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
CVE-2024-363770.000.00May 29, 2024In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
CVE-2024-363760.000.00May 29, 2024In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
CVE-2024-363750.000.00May 29, 2024In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
CVE-2024-363680.000.01May 29, 2024In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
CVE-2024-363650.000.00May 29, 2024In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
CVE-2024-363640.000.00May 29, 2024In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

Page 5 of 9