
CVE-2024-47948
https://notcve.org/view.php?id=CVE-2024-47948
08 Oct 2024 — In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-23: Relative Path Traversal •

CVE-2024-47161
https://notcve.org/view.php?id=CVE-2024-47161
08 Oct 2024 — In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-522: Insufficiently Protected Credentials •

CVE-2024-43810
https://notcve.org/view.php?id=CVE-2024-43810
16 Aug 2024 — In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-43809
https://notcve.org/view.php?id=CVE-2024-43809
16 Aug 2024 — In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-43808
https://notcve.org/view.php?id=CVE-2024-43808
16 Aug 2024 — In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-43807
https://notcve.org/view.php?id=CVE-2024-43807
16 Aug 2024 — In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-43114
https://notcve.org/view.php?id=CVE-2024-43114
06 Aug 2024 — In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-276: Incorrect Default Permissions •

CVE-2024-41829
https://notcve.org/view.php?id=CVE-2024-41829
22 Jul 2024 — In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection En JetBrains TeamCity antes de 2024.07, se podía robar un código OAuth para JetBrains Space a través de la conexión de Space Application. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-303: Incorrect Implementation of Authentication Algorithm •

CVE-2024-41828
https://notcve.org/view.php?id=CVE-2024-41828
22 Jul 2024 — In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time En JetBrains TeamCity antes de 2024.07, la comparación de tokens de autorización no llevaba un tiempo constante • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-208: Observable Timing Discrepancy •

CVE-2024-41827
https://notcve.org/view.php?id=CVE-2024-41827
22 Jul 2024 — In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration En JetBrains TeamCity antes de 2024.07, los tokens de acceso podían seguir funcionando después de su eliminación o vencimiento • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-613: Insufficient Session Expiration •