Vulnerabilities > Jetbrains > Teamcity > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-22 CVE-2024-41828 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
network
low complexity
jetbrains
6.5
2024-07-01 CVE-2024-39878 Insufficiently Protected Credentials vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
network
low complexity
jetbrains CWE-522
5.3
2024-07-01 CVE-2024-39879 Insufficiently Protected Credentials vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
network
low complexity
jetbrains CWE-522
5.3
2024-05-29 CVE-2024-36362 Path Traversal vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
network
low complexity
jetbrains CWE-22
6.5
2024-05-29 CVE-2024-36363 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36364 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
network
low complexity
jetbrains CWE-863
6.5
2024-05-29 CVE-2024-36366 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36367 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
network
low complexity
jetbrains CWE-79
6.1
2024-05-29 CVE-2024-36368 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
network
low complexity
jetbrains CWE-79
5.4
2024-05-29 CVE-2024-36369 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
network
low complexity
jetbrains CWE-79
5.4