Vulnerabilities > Jetbrains > Teamcity > 2023.11.3

DATE CVE VULNERABILITY TITLE RISK
2024-05-29 CVE-2024-36375 Information Exposure Through an Error Message vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
network
low complexity
jetbrains CWE-209
5.3
2024-05-29 CVE-2024-36376 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
network
low complexity
jetbrains CWE-863
8.1
2024-05-29 CVE-2024-36377 Missing Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
network
low complexity
jetbrains CWE-862
8.1
2024-05-29 CVE-2024-36378 Allocation of Resources Without Limits or Throttling vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
network
low complexity
jetbrains CWE-770
7.5
2024-05-29 CVE-2024-36470 Missing Authentication for Critical Function vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
network
low complexity
jetbrains CWE-306
critical
9.8
2024-05-16 CVE-2024-35301 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
network
low complexity
jetbrains
5.5
2024-03-28 CVE-2024-31134 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
network
low complexity
jetbrains CWE-863
6.5
2024-03-28 CVE-2024-31135 Open Redirect vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
network
low complexity
jetbrains CWE-601
6.1
2024-03-28 CVE-2024-31136 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
network
high complexity
jetbrains
7.4
2024-03-28 CVE-2024-31137 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
network
low complexity
jetbrains CWE-79
6.1