
CVE-2022-29927
https://notcve.org/view.php?id=CVE-2022-29927
12 May 2022 — In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible En JetBrains TeamCity versiones anteriores a 2022.04, era posible un ataque de tipo XSS reflejado en la página Build Chain Status • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-25261
https://notcve.org/view.php?id=CVE-2022-25261
25 Feb 2022 — JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS. JetBrains TeamCity antes de 2021.2.2, era vulnerable a un ataque de tipo XSS reflejado. • https://blog.jetbrains.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-25263
https://notcve.org/view.php?id=CVE-2022-25263
25 Feb 2022 — JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. JetBrains TeamCity antes de 2021.2.3, era vulnerable a una inyección de comandos del Sistema Operativo en la configuración de la función Agent Push. • https://blog.jetbrains.com • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2022-25264
https://notcve.org/view.php?id=CVE-2022-25264
25 Feb 2022 — In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. En JetBrains TeamCity antes de 2021.2.3, las variables de entorno del tipo "password" podían registrarse en algunos casos. • https://blog.jetbrains.com • CWE-922: Insecure Storage of Sensitive Information •

CVE-2022-24342
https://notcve.org/view.php?id=CVE-2022-24342
25 Feb 2022 — In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. En JetBrains TeamCity versiones anteriores a 2021.2.1, era posible una inyección de URL que conllevaba a un ataque de tipo CSRF. • https://github.com/yuriisanin/CVE-2022-24342 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-24341
https://notcve.org/view.php?id=CVE-2022-24341
25 Feb 2022 — In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user. En JetBrains TeamCity versiones anteriores a 2021.2.1, la edición de una cuenta de usuario para cambiar su contraseña no terminaba las sesiones del usuario editado. • https://blog.jetbrains.com • CWE-613: Insufficient Session Expiration •

CVE-2022-24340
https://notcve.org/view.php?id=CVE-2022-24340
25 Feb 2022 — In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. En JetBrains TeamCity versiones anteriores a 2021.2.1, era posible que se produjera un error de tipo XXE durante el análisis del archivo de configuración. • https://blog.jetbrains.com • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2022-24339
https://notcve.org/view.php?id=CVE-2022-24339
25 Feb 2022 — JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. JetBrains TeamCity versiones anteriores a 2021.2.1 era vulnerable a un ataque de tipo XSS almacenado. • https://blog.jetbrains.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-24338
https://notcve.org/view.php?id=CVE-2022-24338
25 Feb 2022 — JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. JetBrains TeamCity versiones anteriores a 2021.2.1 era vulnerable a un ataque de tipo XSS reflejado. • https://blog.jetbrains.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-24337
https://notcve.org/view.php?id=CVE-2022-24337
25 Feb 2022 — In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions. En JetBrains TeamCity versiones anteriores a 2021.2, los elementos de salud de las peticiones de extracción eran mostrados a usuarios que carecían de los permisos apropiados. • https://blog.jetbrains.com • CWE-276: Incorrect Default Permissions •