| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible |
| In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible |
| In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed |
| In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly |
| JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request. |
| In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection |
| In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time |
| In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration |
| In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page |
| In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab |
| In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases |
| In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings |
| In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection |
| In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings |
| In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration |
| In JetBrains TeamCity before 2024.03 open redirect was possible on the login page |
| In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives |
| In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible |
| In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed |
| In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible |