Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
teamcity vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-15848
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
Jetbrains Teamcity 2019.1
Jetbrains Teamcity 2019.1.1
5.3
CVSSv3
CVE-2019-18363
In JetBrains TeamCity prior to 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
Jetbrains Teamcity
9.8
CVSSv3
CVE-2019-18364
In JetBrains TeamCity prior to 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
Jetbrains Teamcity
4.3
CVSSv3
CVE-2019-18365
In JetBrains TeamCity prior to 2019.1.4, reverse tabnabbing was possible on several pages.
Jetbrains Teamcity
5.3
CVSSv3
CVE-2019-18366
In JetBrains TeamCity prior to 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
Jetbrains Teamcity
5.3
CVSSv3
CVE-2019-18367
In JetBrains TeamCity prior to 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
Jetbrains Teamcity
8.1
CVSSv3
CVE-2022-24335
JetBrains TeamCity prior to 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
Jetbrains Teamcity
6.5
CVSSv3
CVE-2022-24337
In JetBrains TeamCity prior to 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.
Jetbrains Teamcity
5.4
CVSSv3
CVE-2022-24339
JetBrains TeamCity prior to 2021.2.1 was vulnerable to stored XSS.
Jetbrains Teamcity
9.8
CVSSv3
CVE-2022-24340
In JetBrains TeamCity prior to 2021.2.1, XXE during the parsing of the configuration file was possible.
Jetbrains Teamcity
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »