Vulnerabilities > Jetbrains > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-05-29 CVE-2024-36366 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36367 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36368 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36369 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36370 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36372 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36373 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36374 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36375 Information Exposure Through an Error Message vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
network
low complexity
jetbrains CWE-209
5.3
2024-05-16 CVE-2024-35300 Cross-site Scripting vulnerability in Jetbrains Teamcity 2024.03
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
network
low complexity
jetbrains CWE-79
6.1