Filtered by vendor Jetbrains Subscriptions
Filtered by product Teamcity Subscriptions
Total 168 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-31913 1 Jetbrains 1 Teamcity 2024-08-03 7.5 High
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.
CVE-2021-31914 2 Jetbrains, Microsoft 2 Teamcity, Windows 2024-08-03 9.8 Critical
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
CVE-2021-26309 1 Jetbrains 1 Teamcity 2024-08-03 3.3 Low
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
CVE-2021-26310 1 Jetbrains 1 Teamcity 2024-08-03 7.5 High
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
CVE-2021-25777 1 Jetbrains 1 Teamcity 2024-08-03 5.3 Medium
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
CVE-2021-25778 1 Jetbrains 1 Teamcity 2024-08-03 5.3 Medium
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
CVE-2021-25776 1 Jetbrains 1 Teamcity 2024-08-03 7.5 High
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
CVE-2021-25772 1 Jetbrains 1 Teamcity 2024-08-03 5.3 Medium
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
CVE-2021-25773 1 Jetbrains 1 Teamcity 2024-08-03 6.1 Medium
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
CVE-2021-25774 1 Jetbrains 1 Teamcity 2024-08-03 4.3 Medium
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
CVE-2021-25775 1 Jetbrains 1 Teamcity 2024-08-03 3.8 Low
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
CVE-2021-3315 1 Jetbrains 1 Teamcity 2024-08-03 5.4 Medium
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
CVE-2022-48426 1 Jetbrains 1 Teamcity 2024-08-03 4.6 Medium
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
CVE-2022-48427 1 Jetbrains 1 Teamcity 2024-08-03 4.6 Medium
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
CVE-2022-48428 1 Jetbrains 1 Teamcity 2024-08-03 4.6 Medium
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVE-2022-48343 1 Jetbrains 1 Teamcity 2024-08-03 5.4 Medium
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-48344 1 Jetbrains 1 Teamcity 2024-08-03 5.4 Medium
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-48342 1 Jetbrains 1 Teamcity 2024-08-03 5.2 Medium
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-46831 1 Jetbrains 1 Teamcity 2024-08-03 6.6 Medium
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVE-2022-46830 1 Jetbrains 1 Teamcity 2024-08-03 4.1 Medium
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.