CVE-2021-31914
https://notcve.org/view.php?id=CVE-2021-31914
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. En JetBrains TeamCity versiones anteriores a 2020.2.4 en Windows, fue posible una ejecución de código arbitrario en TeamCity Server • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021 •
CVE-2021-31913
https://notcve.org/view.php?id=CVE-2021-31913
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. En JetBrains TeamCity versiones anteriores a 2020.2.3, se realizaron comprobaciones insuficientes de la función redirect_uri durante el intercambio de tokens de SSO de GitHub • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021 • CWE-354: Improper Validation of Integrity Check Value •
CVE-2021-31912
https://notcve.org/view.php?id=CVE-2021-31912
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. En JetBrains TeamCity versiones anteriores a 2020.2.3, la toma de control de la cuenta fue potencialmente posible durante un restablecimiento de contraseña • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021 • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •
CVE-2021-31911
https://notcve.org/view.php?id=CVE-2021-31911
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. En JetBrains TeamCity versiones anteriores a 2020.2.3, una vulnerabilidad de tipo XSS reflejado fue posible en varias páginas • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-31910
https://notcve.org/view.php?id=CVE-2021-31910
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. En JetBrains TeamCity versiones anteriores a 2020.2.3, fue posible una divulgación de información por medio de un ataque de tipo SSRF • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021 • CWE-918: Server-Side Request Forgery (SSRF) •