| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page |
| In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources |
| In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab |
| In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log |
| In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page |
| In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page |
| In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs |
| In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible |
| In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab |
| In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters |
| In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings |
| In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive |
| In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings |
| In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. |
| In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators. |
| Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html. |
| Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors. |
| In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents. |
| In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process. |
| In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. |