Product:

Teamcity

(Jetbrains)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 197
Date Id Summary Products Score Patch Annotated
2024-12-20 CVE-2024-56355 In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS Teamcity 5.4
2024-12-20 CVE-2024-56356 In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack Teamcity 7.1
2024-03-04 CVE-2024-27199 In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible Teamcity 7.3
2024-03-06 CVE-2024-28173 In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed Teamcity 4.3
2024-03-06 CVE-2024-28174 In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly Teamcity 5.8
2024-03-21 CVE-2024-29880 In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process Teamcity 7.8
2024-03-28 CVE-2024-31134 In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled Teamcity 6.5
2024-03-28 CVE-2024-31136 In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter Teamcity 7.4
2024-03-28 CVE-2024-31139 In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector Teamcity 8.1
2024-03-28 CVE-2024-31140 In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools Teamcity 4.9