Vulnerabilities > Jetbrains > Teamcity > 10.0.5

DATE CVE VULNERABILITY TITLE RISK
2019-10-02 CVE-2019-12157 Improper Input Validation vulnerability in Jetbrains Teamcity and Upsource
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
network
low complexity
jetbrains CWE-20
critical
10.0
2019-07-03 CVE-2019-12846 Unspecified vulnerability in Jetbrains Teamcity
A user without the required permissions could gain access to some JetBrains TeamCity settings.
network
low complexity
jetbrains
4.0
2019-07-03 CVE-2019-12845 Improper Authentication vulnerability in Jetbrains Teamcity
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts.
network
low complexity
jetbrains CWE-287
5.0
2019-07-03 CVE-2019-12844 Code Injection vulnerability in Jetbrains Teamcity
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages.
network
jetbrains CWE-94
4.3
2019-07-03 CVE-2019-12843 Code Injection vulnerability in Jetbrains Teamcity
A possible stored JavaScript injection requiring a deliberate server administrator action was detected.
network
jetbrains CWE-94
4.3
2019-07-03 CVE-2019-12842 Cross-site Scripting vulnerability in Jetbrains Teamcity
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages.
network
jetbrains CWE-79
4.3
2019-07-03 CVE-2019-12841 Improper Input Validation vulnerability in Jetbrains Teamcity
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity.
network
low complexity
jetbrains CWE-20
5.0