Vulnerabilities > Jetbrains > Teamcity > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-31 CVE-2019-18366 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
network
low complexity
jetbrains CWE-276
5.3
2019-10-31 CVE-2019-18365 Improper Privilege Management vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
network
low complexity
jetbrains CWE-269
4.3
2019-10-31 CVE-2019-18363 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
network
low complexity
jetbrains
5.3
2019-10-02 CVE-2019-15037 Cross-site Scripting vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
low complexity
jetbrains CWE-79
6.1
2019-10-01 CVE-2019-15035 Unspecified vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
low complexity
jetbrains
4.9
2019-09-05 CVE-2019-15848 Cross-site Scripting vulnerability in Jetbrains Teamcity 2019.1/2019.1.1
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
network
low complexity
jetbrains CWE-79
6.1
2019-07-03 CVE-2019-12846 Unspecified vulnerability in Jetbrains Teamcity
A user without the required permissions could gain access to some JetBrains TeamCity settings.
network
low complexity
jetbrains
4.3
2019-07-03 CVE-2019-12845 Improper Authentication vulnerability in Jetbrains Teamcity
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts.
network
low complexity
jetbrains CWE-287
5.3
2019-07-03 CVE-2019-12844 Code Injection vulnerability in Jetbrains Teamcity
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages.
network
low complexity
jetbrains CWE-94
6.1
2019-07-03 CVE-2019-12843 Code Injection vulnerability in Jetbrains Teamcity
A possible stored JavaScript injection requiring a deliberate server administrator action was detected.
network
low complexity
jetbrains CWE-94
6.1