VYPR

Teamcity

by Jetbrains

Source repositories

CVEs (166)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2024-363620.000.00May 29, 2024In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
CVE-2024-353010.000.00May 16, 2024In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
CVE-2024-353000.000.01May 16, 2024In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
CVE-2024-311400.000.00Mar 28, 2024In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
CVE-2024-311390.000.00Mar 28, 2024In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
CVE-2024-311380.000.05Mar 28, 2024In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
CVE-2024-311370.000.00Mar 28, 2024In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
CVE-2024-311360.000.00Mar 28, 2024In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
CVE-2024-311350.000.00Mar 28, 2024In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
CVE-2024-311340.000.00Mar 28, 2024In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
CVE-2024-298800.000.00Mar 21, 2024In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
CVE-2024-281740.000.00Mar 6, 2024In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
CVE-2024-281730.000.00Mar 6, 2024In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
CVE-2024-249420.000.00Feb 6, 2024In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
CVE-2024-249380.000.00Feb 6, 2024In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
CVE-2024-249370.000.00Feb 6, 2024In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
CVE-2024-249360.000.00Feb 6, 2024In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
CVE-2023-508700.000.00Dec 15, 2023In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
CVE-2023-435660.000.00Sep 19, 2023In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
CVE-2023-412500.000.00Aug 25, 2023In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration

Page 6 of 9