Vulnerabilities > Jetbrains > Teamcity > 2022.04.7

DATE CVE VULNERABILITY TITLE RISK
2024-12-20 CVE-2024-56354 Insufficiently Protected Credentials vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
network
low complexity
jetbrains CWE-522
4.9
2024-12-20 CVE-2024-56355 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
network
low complexity
jetbrains CWE-79
5.4
2024-12-20 CVE-2024-56356 XXE vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
network
low complexity
jetbrains CWE-611
7.1
2024-05-29 CVE-2024-36371 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36372 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36373 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36374 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36375 Information Exposure Through an Error Message vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
network
low complexity
jetbrains CWE-209
5.3
2024-05-29 CVE-2024-36376 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
network
low complexity
jetbrains CWE-863
8.1
2024-05-29 CVE-2024-36377 Missing Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
network
low complexity
jetbrains CWE-862
8.1