VYPR

by Jetbrains

Source repositories

CVEs (166)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2023-342220.000.00May 31, 2023In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
CVE-2023-342210.000.00May 31, 2023In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
CVE-2023-342200.000.05May 31, 2023In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2023-342190.000.00May 31, 2023In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
CVE-2023-342180.000.00May 31, 2023In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
CVE-2022-484280.000.01Mar 27, 2023In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVE-2022-484270.000.00Mar 27, 2023In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
CVE-2022-484260.000.00Mar 27, 2023In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
CVE-2022-483440.000.00Feb 23, 2023In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-483430.000.01Feb 23, 2023In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-483420.000.00Feb 23, 2023In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-468310.000.00Dec 8, 2022In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVE-2022-468300.000.00Dec 8, 2022In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-446220.000.00Nov 3, 2022In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
CVE-2022-446460.000.00Nov 3, 2022In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
CVE-2022-446240.000.00Nov 3, 2022In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
CVE-2022-446230.000.00Nov 3, 2022In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
CVE-2022-409790.000.00Sep 23, 2022In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
CVE-2022-381330.000.00Aug 10, 2022In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
CVE-2022-363220.000.00Jul 20, 2022In JetBrains TeamCity before 2022.04.2 build parameter injection was possible

Page 8 of 9