Product:

Teamcity

(Jetbrains)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 197
Date Id Summary Products Score Patch Annotated
2024-03-06 CVE-2024-28173 In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed Teamcity 4.3
2024-03-06 CVE-2024-28174 In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly Teamcity 5.8
2024-03-21 CVE-2024-29880 In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process Teamcity 7.8
2024-03-28 CVE-2024-31134 In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled Teamcity 6.5
2024-03-28 CVE-2024-31136 In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter Teamcity 7.4
2024-03-28 CVE-2024-31139 In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector Teamcity 8.1
2024-03-28 CVE-2024-31140 In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools Teamcity 4.9
2024-05-16 CVE-2024-35300 In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible Teamcity 6.1
2024-05-16 CVE-2024-35301 In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token Teamcity 5.5
2024-05-16 CVE-2024-35302 In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible Teamcity 6.1