CVE-2021-37546
https://notcve.org/view.php?id=CVE-2021-37546
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. En JetBrains TeamCity versiones anteriores a 2021.1, era usado un mecanismo no seguro de generación de claves para las propiedades cifradas • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2021-37545
https://notcve.org/view.php?id=CVE-2021-37545
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. En JetBrains TeamCity versiones anteriores a 2021.1.1, se realizaban comprobaciones insuficientes de autenticación para las peticiones de los agentes • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-287: Improper Authentication •
CVE-2021-37544
https://notcve.org/view.php?id=CVE-2021-37544
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. En JetBrains TeamCity versiones anteriores a 2020.2.4, había una deserialización no segura • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-502: Deserialization of Untrusted Data •
CVE-2021-37542
https://notcve.org/view.php?id=CVE-2021-37542
In JetBrains TeamCity before 2020.2.3, XSS was possible. En JetBrains TeamCity versiones anteriores a 2020.2.3, era posible una ejecución de un ataque de tipo XSS • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-31915
https://notcve.org/view.php?id=CVE-2021-31915
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. En JetBrains TeamCity versiones anteriores a 2020.2.4, fue posible una inyección de comandos del Sistema Operativo conllevando a una ejecución de código remota • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •