CVE-2021-25775
https://notcve.org/view.php?id=CVE-2021-25775
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. En JetBrains TeamCity versiones anteriores a 2020.2.1, el administrador del servidor podía crear y visualizar tokens de acceso para cualquier otro usuario • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 •
CVE-2021-25774
https://notcve.org/view.php?id=CVE-2021-25774
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. En JetBrains TeamCity versiones anteriores a 2020.2.1, un usuario podía conseguir acceso a un token de acceso de GitHub de otro usuario • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 • CWE-863: Incorrect Authorization •
CVE-2021-25776
https://notcve.org/view.php?id=CVE-2021-25776
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. En JetBrains TeamCity versiones anteriores a 2020.2, un token ECR podría estar expuesto en unos parámetros de compilación • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 • CWE-922: Insecure Storage of Sensitive Information •
CVE-2021-25772
https://notcve.org/view.php?id=CVE-2021-25772
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. En JetBrains TeamCity versiones anteriores a 2020.2.2, una DoS del servidor de TeamCity fue posible por medio de una integración del servidor • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 •
CVE-2021-25773
https://notcve.org/view.php?id=CVE-2021-25773
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. JetBrains TeamCity versiones anteriores a 2020.2, era vulnerable a un ataque de tipo XSS reflejado en varias páginas • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •