Vulnerabilities > Jetbrains > Teamcity > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-08 CVE-2024-47948 Path Traversal vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
network
low complexity
jetbrains CWE-22
7.5
2024-10-08 CVE-2024-47949 Path Traversal vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
network
low complexity
jetbrains CWE-22
7.5
2024-08-06 CVE-2024-43114 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
local
low complexity
jetbrains CWE-276
7.8
2024-07-22 CVE-2024-41829 Improper Authentication vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
network
low complexity
jetbrains CWE-287
7.5
2024-05-29 CVE-2024-36365 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
network
low complexity
jetbrains CWE-863
8.1
2024-03-28 CVE-2024-31136 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
network
high complexity
jetbrains
7.4
2024-03-28 CVE-2024-31139 XXE vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
network
low complexity
jetbrains CWE-611
8.1
2024-03-21 CVE-2024-29880 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
local
low complexity
jetbrains
7.8
2024-03-04 CVE-2024-27199 Path Traversal vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
network
low complexity
jetbrains CWE-22
7.3
2023-12-15 CVE-2023-50870 Cross-Site Request Forgery (CSRF) vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
network
low complexity
jetbrains CWE-352
8.8