Vulnerabilities > Jetbrains > Teamcity > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-31 CVE-2023-34226 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible
network
low complexity
jetbrains CWE-79
6.1
2023-05-31 CVE-2023-34228 Use of Single-factor Authentication vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
network
low complexity
jetbrains CWE-308
6.5
2023-05-31 CVE-2023-34229 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
network
low complexity
jetbrains CWE-79
5.4
2023-03-27 CVE-2022-48427 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
network
low complexity
jetbrains CWE-79
5.4
2023-03-27 CVE-2022-48428 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
network
low complexity
jetbrains CWE-79
5.4
2023-03-27 CVE-2022-48426 Cross-site Scripting vulnerability in Jetbrains Teamcity 2022.10.3
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
network
low complexity
jetbrains CWE-79
5.4
2023-02-23 CVE-2022-48343 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
network
low complexity
jetbrains CWE-79
6.1
2023-02-23 CVE-2022-48344 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
network
low complexity
jetbrains CWE-79
6.1
2022-12-08 CVE-2022-46830 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Teamcity 2022.10/2022.10.1
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
network
low complexity
jetbrains CWE-918
5.3
2022-12-08 CVE-2022-46831 Insecure Default Initialization of Resource vulnerability in Jetbrains Teamcity 2022.10/2022.10.1
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
network
low complexity
jetbrains CWE-1188
4.9