Show filters
211 Total Results
Displaying 31-40 of 211
Sort by:
Attacker Value
Unknown

CVE-2024-41828

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
Attacker Value
Unknown

CVE-2024-41827

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
Attacker Value
Unknown

CVE-2024-41826

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
Attacker Value
Unknown

CVE-2024-41825

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
Attacker Value
Unknown

CVE-2024-41824

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
Attacker Value
Unknown

CVE-2024-39879

Disclosure Date: July 01, 2024 (last updated September 18, 2024)
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
Attacker Value
Unknown

CVE-2024-39878

Disclosure Date: July 01, 2024 (last updated September 18, 2024)
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
Attacker Value
Unknown

CVE-2024-36470

Disclosure Date: May 29, 2024 (last updated February 08, 2025)
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
Attacker Value
Unknown

CVE-2024-36378

Disclosure Date: May 29, 2024 (last updated January 28, 2025)
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
Attacker Value
Unknown

CVE-2024-36377

Disclosure Date: May 29, 2024 (last updated January 28, 2025)
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions