Loading HuntDB...

Version 0

SINGLE_NUMBER 97 CVEs

Known Vulnerabilities

CVE-2024-56356

In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

MEDIUM CVSS 5.9 Published Dec 20, 2024

CVE-2024-56355

In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

MEDIUM CVSS 4.6 Published Dec 20, 2024

CVE-2024-56354

In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission

MEDIUM CVSS 5.5 Published Dec 20, 2024

CVE-2024-56353

In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies

MEDIUM CVSS 5.5 Published Dec 20, 2024

CVE-2024-56352

In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page

MEDIUM CVSS 4.6 Published Dec 20, 2024

CVE-2024-56351

In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

MEDIUM CVSS 6.3 Published Dec 20, 2024

CVE-2024-56350

In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

MEDIUM CVSS 4.3 Published Dec 20, 2024

CVE-2024-56349

In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs

MEDIUM CVSS 5.3 Published Dec 20, 2024

CVE-2024-56348

In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

MEDIUM CVSS 4.3 Published Dec 20, 2024

CVE-2024-47951

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

LOW CVSS 3.5 Published Oct 08, 2024

CVE-2024-47950

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

LOW CVSS 3.5 Published Oct 08, 2024

CVE-2024-47949

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

MEDIUM CVSS 4.9 Published Oct 08, 2024

CVE-2024-47948

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

MEDIUM CVSS 4.9 Published Oct 08, 2024

CVE-2024-47161

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

MEDIUM CVSS 4.3 Published Oct 08, 2024

CVE-2024-43810

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

MEDIUM CVSS 4.6 Published Aug 16, 2024

CVE-2024-43809

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

LOW CVSS 3.5 Published Aug 16, 2024

CVE-2024-43808

In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin

LOW CVSS 3.7 Published Aug 16, 2024

CVE-2024-43807

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

MEDIUM CVSS 4.6 Published Aug 16, 2024

CVE-2024-43114

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

HIGH CVSS 7.5 Published Aug 06, 2024

CVE-2024-41829

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

LOW CVSS 3.5 Published Jul 22, 2024

CVE-2024-41828

In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

LOW CVSS 2.6 Published Jul 22, 2024

CVE-2024-41827

In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

HIGH CVSS 7.4 Published Jul 22, 2024

CVE-2024-41826

In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

LOW CVSS 3.5 Published Jul 22, 2024

CVE-2024-41825

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

MEDIUM CVSS 4.6 Published Jul 22, 2024

CVE-2024-41824

In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

MEDIUM CVSS 6.4 Published Jul 22, 2024

CVE-2024-39879

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

MEDIUM CVSS 5.0 Published Jul 01, 2024

CVE-2024-39878

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

MEDIUM CVSS 4.1 Published Jul 01, 2024

CVE-2024-36470

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

HIGH CVSS 8.1 Published May 29, 2024

CVE-2024-36378

In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens

MEDIUM CVSS 5.9 Published May 29, 2024

CVE-2024-36377

In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

MEDIUM CVSS 6.5 Published May 29, 2024

CVE-2024-36376

In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

MEDIUM CVSS 6.5 Published May 29, 2024

CVE-2024-36375

In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

MEDIUM CVSS 5.3 Published May 29, 2024

CVE-2024-36374

In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36373

In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36372

In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36371

In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36370

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36369

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36368

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36367

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36366

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations

MEDIUM CVSS 5.4 Published May 29, 2024

CVE-2024-36365

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

MEDIUM CVSS 6.8 Published May 29, 2024

CVE-2024-36364

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

MEDIUM CVSS 6.5 Published May 29, 2024

CVE-2024-36363

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible

MEDIUM CVSS 4.6 Published May 29, 2024

CVE-2024-36362

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

MEDIUM CVSS 6.5 Published May 29, 2024

CVE-2024-35302

In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible

MEDIUM CVSS 5.4 Published May 16, 2024

CVE-2024-35301

In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

MEDIUM CVSS 5.5 Published May 16, 2024

CVE-2024-31140

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

MEDIUM CVSS 4.1 Published Mar 28, 2024

CVE-2024-31139

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

MEDIUM CVSS 5.9 Published Mar 28, 2024

CVE-2024-31138

In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

MEDIUM CVSS 4.6 Published Mar 28, 2024

CVE-2024-31137

In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

MEDIUM CVSS 6.8 Published Mar 28, 2024

CVE-2024-31136

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

HIGH CVSS 7.4 Published Mar 28, 2024

CVE-2024-31135

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

MEDIUM CVSS 6.1 Published Mar 28, 2024

CVE-2024-31134

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

MEDIUM CVSS 6.5 Published Mar 28, 2024

CVE-2024-29880

In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

MEDIUM CVSS 4.2 Published Mar 21, 2024

CVE-2024-28174

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

MEDIUM CVSS 5.8 Published Mar 06, 2024

CVE-2024-27199

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

HIGH CVSS 7.3 Published Mar 04, 2024

CVE-2024-27198

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CRITICAL CVSS 9.8 Published Mar 04, 2024

CVE-2024-23917

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

CRITICAL CVSS 9.8 Published Feb 06, 2024

CVE-2024-24942

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

MEDIUM CVSS 5.3 Published Feb 06, 2024

CVE-2024-24938

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

MEDIUM CVSS 5.3 Published Feb 06, 2024

CVE-2024-24937

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

MEDIUM CVSS 4.6 Published Feb 06, 2024

CVE-2024-24936

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

MEDIUM CVSS 4.3 Published Feb 06, 2024

CVE-2023-50870

In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible

MEDIUM CVSS 4.3 Published Dec 15, 2023

CVE-2023-43566

In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration

LOW CVSS 3.5 Published Sep 19, 2023

CVE-2023-42793

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

CRITICAL CVSS 9.8 Published Sep 19, 2023

CVE-2023-41250

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration

LOW CVSS 3.5 Published Aug 25, 2023

CVE-2023-41249

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

MEDIUM CVSS 4.6 Published Aug 25, 2023

CVE-2023-41248

In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration

MEDIUM CVSS 4.6 Published Aug 25, 2023

CVE-2023-39175

In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible

MEDIUM CVSS 4.6 Published Jul 25, 2023

CVE-2023-39174

In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

MEDIUM CVSS 4.3 Published Jul 25, 2023

CVE-2023-39173

In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access

MEDIUM CVSS 5.4 Published Jul 25, 2023

CVE-2023-38067

In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

MEDIUM CVSS 4.3 Published Jul 12, 2023

CVE-2023-38066

In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads

MEDIUM CVSS 4.6 Published Jul 12, 2023

CVE-2023-38065

In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible

MEDIUM CVSS 4.6 Published Jul 12, 2023

CVE-2023-38064

In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

MEDIUM CVSS 4.3 Published Jul 12, 2023

CVE-2023-38063

In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible

MEDIUM CVSS 4.6 Published Jul 12, 2023

CVE-2023-38062

In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

MEDIUM CVSS 4.3 Published Jul 12, 2023

CVE-2023-38061

In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible

MEDIUM CVSS 4.6 Published Jul 12, 2023

CVE-2023-34229

In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible

MEDIUM CVSS 4.6 Published May 31, 2023

CVE-2023-34228

In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions

MEDIUM CVSS 5.3 Published May 31, 2023

CVE-2023-34227

In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks

MEDIUM CVSS 5.3 Published May 31, 2023

CVE-2023-34226

In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible

MEDIUM CVSS 4.6 Published May 31, 2023

CVE-2023-34225

In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible

MEDIUM CVSS 4.6 Published May 31, 2023

CVE-2023-34224

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible

MEDIUM CVSS 4.8 Published May 31, 2023

CVE-2023-34223

In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

MEDIUM CVSS 4.3 Published May 31, 2023

CVE-2023-34222

In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible

MEDIUM CVSS 4.6 Published May 31, 2023

CVE-2023-34221

In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible

MEDIUM CVSS 4.6 Published May 31, 2023

CVE-2023-34220

In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible

MEDIUM CVSS 4.6 Published May 31, 2023

CVE-2023-34219

In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

MEDIUM CVSS 4.3 Published May 31, 2023

CVE-2023-34218

In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible

CRITICAL CVSS 9.1 Published May 31, 2023

CVE-2022-48428

In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible

MEDIUM CVSS 4.6 Published Mar 27, 2023

CVE-2022-48427

In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible

MEDIUM CVSS 4.6 Published Mar 27, 2023

CVE-2022-48426

In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible

MEDIUM CVSS 4.6 Published Mar 27, 2023

CVE-2022-48344

In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.

MEDIUM CVSS 5.4 Published Feb 23, 2023

CVE-2022-48343

In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.

MEDIUM CVSS 5.4 Published Feb 23, 2023

CVE-2022-48342

In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

MEDIUM CVSS 5.2 Published Feb 23, 2023