Vulnerabilities > Jetbrains > Teamcity > 2020.2.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-11 | CVE-2021-31912 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. | 6.8 |
2021-05-11 | CVE-2021-31913 | Improper Validation of Integrity Check Value vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. | 5.0 |
2021-05-11 | CVE-2021-31914 | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. | 7.5 |
2021-05-11 | CVE-2021-31915 | OS Command Injection vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. | 7.5 |
2021-05-11 | CVE-2021-31908 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages. | 3.5 |
2021-05-11 | CVE-2021-31909 | Argument Injection or Modification vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. | 7.5 |
2021-02-03 | CVE-2020-35667 | Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Teamcity JetBrains TeamCity Plugin before 2020.2.85695 SSRF. | 5.0 |