Vulnerabilities > Jetbrains > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-06 | CVE-2024-24942 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | 5.3 |
2024-02-06 | CVE-2024-24943 | Resource Exhaustion vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | 5.5 |
2024-01-09 | CVE-2024-22370 | Cross-site Scripting vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | 5.4 |
2023-12-15 | CVE-2023-50871 | Unspecified vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | 4.3 |
2023-09-19 | CVE-2023-43566 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration | 5.4 |
2023-08-25 | CVE-2023-41248 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration | 5.4 |
2023-08-25 | CVE-2023-41249 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | 6.1 |
2023-08-25 | CVE-2023-41250 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | 6.1 |
2023-07-25 | CVE-2023-39175 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible | 6.1 |
2023-07-12 | CVE-2023-38061 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible | 5.4 |