Vulnerabilities > Jetbrains > Teamcity > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-11-03 CVE-2022-44622 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
network
low complexity
jetbrains
5.3
2022-11-03 CVE-2022-44646 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
network
low complexity
jetbrains
5.3
2022-09-23 CVE-2022-40979 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
network
low complexity
jetbrains CWE-532
5.3
2022-08-10 CVE-2022-38133 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
network
low complexity
jetbrains CWE-532
5.3
2022-07-20 CVE-2022-36321 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
network
low complexity
jetbrains CWE-532
6.5
2022-05-12 CVE-2022-29927 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
network
low complexity
jetbrains CWE-79
6.1
2022-05-12 CVE-2022-29928 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
network
low complexity
jetbrains CWE-532
4.9
2022-05-12 CVE-2022-29929 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
network
low complexity
jetbrains CWE-79
6.1
2022-02-25 CVE-2022-25261 Cross-site Scripting vulnerability in Jetbrains Teamcity
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
network
low complexity
jetbrains CWE-79
6.1
2022-02-25 CVE-2022-24330 Open Redirect vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
network
low complexity
jetbrains CWE-601
6.1