JetBrains

Teamcity

243 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:47

In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

  • EPSS 7.72%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:47

In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible

  • EPSS 0.08%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:47

In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible

  • EPSS 0.03%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible

  • EPSS 0%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

  • EPSS 0%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible

  • EPSS 6.05%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible

  • EPSS 0.03%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible

  • EPSS 0%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks

  • EPSS 0%
  • Published 31.05.2023 14:15:10
  • Last modified 21.11.2024 08:06:48

In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions