Vulnerabilities > Jetbrains > Teamcity > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-03-06 | CVE-2024-28174 | Incorrect Authorization vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly | 5.8 |
2024-02-06 | CVE-2024-24936 | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed | 5.3 |
2024-02-06 | CVE-2024-24937 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible | 5.4 |
2024-02-06 | CVE-2024-24938 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation | 5.3 |
2024-02-06 | CVE-2024-24942 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | 5.3 |
2023-09-19 | CVE-2023-43566 | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration | 5.4 |
2023-08-25 | CVE-2023-41248 | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration | 5.4 |
2023-08-25 | CVE-2023-41249 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | 6.1 |
2023-08-25 | CVE-2023-41250 | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | 6.1 |
2023-07-25 | CVE-2023-39175 | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible | 6.1 |