Vulnerabilities > Jetbrains > Teamcity > 2017.2.4

DATE CVE VULNERABILITY TITLE RISK
2023-09-19 CVE-2023-42793 Authentication Bypass Using an Alternate Path or Channel vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
network
low complexity
jetbrains CWE-288
critical
9.8
2023-09-19 CVE-2023-43566 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
network
low complexity
jetbrains CWE-79
5.4
2023-08-25 CVE-2023-41248 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration
network
low complexity
jetbrains CWE-79
5.4
2023-08-25 CVE-2023-41249 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
network
low complexity
jetbrains CWE-79
6.1
2023-08-25 CVE-2023-41250 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
network
low complexity
jetbrains CWE-79
6.1
2023-07-25 CVE-2023-39173 Incorrect Privilege Assignment vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
network
low complexity
jetbrains CWE-266
8.8
2023-07-25 CVE-2023-39174 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers
network
low complexity
jetbrains
7.5
2023-07-25 CVE-2023-39175 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible
network
low complexity
jetbrains CWE-79
6.1
2023-07-12 CVE-2023-38061 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible
network
low complexity
jetbrains CWE-79
5.4
2023-07-12 CVE-2023-38062 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
network
low complexity
jetbrains
6.5