
CVE-2022-48427
https://notcve.org/view.php?id=CVE-2022-48427
27 Mar 2023 — In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-48344
https://notcve.org/view.php?id=CVE-2022-48344
23 Feb 2023 — In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-48343
https://notcve.org/view.php?id=CVE-2022-48343
23 Feb 2023 — In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-48342
https://notcve.org/view.php?id=CVE-2022-48342
23 Feb 2023 — In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-1188: Initialization of a Resource with an Insecure Default •

CVE-2022-44646
https://notcve.org/view.php?id=CVE-2022-44646
03 Nov 2022 — In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings En la versión JetBrains TeamCity anterior a 2022.10, no se agregaron elementos de auditoría al editar la configuración de un usuario • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-223: Omission of Security-relevant Information •

CVE-2022-44623
https://notcve.org/view.php?id=CVE-2022-44623
03 Nov 2022 — In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings En la versión JetBrains TeamCity anterior a 2022.10, Project Viewer podía ver valores seguros codificados en la configuración de MetaRunner. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory •

CVE-2022-44624
https://notcve.org/view.php?id=CVE-2022-44624
03 Nov 2022 — In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters En la versión JetBrains TeamCity anterior a 2022.10, los parámetros de contraseña podían quedar expuestos en el registro de compilación si contenían caracteres especiales. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2022-40979
https://notcve.org/view.php?id=CVE-2022-40979
23 Sep 2022 — In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable En JetBrains TeamCity versiones anteriores a 2022.04.4, las variables de entorno de tipo "password" podían registrarse cuando era usado un ejecutable Perforce personalizado • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2022-38133
https://notcve.org/view.php?id=CVE-2022-38133
10 Aug 2022 — In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases En JetBrains TeamCity versiones anteriores a 2022.04.3, la clave SSH privada podría escribirse en el registro del servidor en algunos casos • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2022-36322
https://notcve.org/view.php?id=CVE-2022-36322
20 Jul 2022 — In JetBrains TeamCity before 2022.04.2 build parameter injection was possible En JetBrains TeamCity versiones anteriores a 2022.04.2, era posible la inyección de parámetros de construcción • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') •