Page 6 of 209 results (0.001 seconds)

CVSS: 6.5EPSS: 0%CPEs: 4EXPL: 0

29 May 2024 — In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible En JetBrains TeamCity antes de 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5 era posible un control de acceso inadecuado en las funciones de compilación del editor de estado de confirmación y solicitudes de extracción • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-863: Incorrect Authorization •

CVSS: 4.6EPSS: 55%CPEs: 4EXPL: 0

29 May 2024 — In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible En JetBrains TeamCity antes de 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5 eran posibles varios XSS almacenados en informes de inspección de código. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

29 May 2024 — In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible En JetBrains TeamCity antes de 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5, 2024.03.2 era posible path traversal permitiendo leer archivos del servidor • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-23: Relative Path Traversal •

CVSS: 5.4EPSS: 12%CPEs: 1EXPL: 0

16 May 2024 — In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

16 May 2024 — In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-280: Improper Handling of Insufficient Permissions or Privileges •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

28 Mar 2024 — In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools En JetBrains TeamCity antes de 2024.03, los administradores del servidor podían eliminar archivos arbitrarios del servidor instalando herramientas • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-1288: Improper Validation of Consistency within Input •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

28 Mar 2024 — In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector En JetBrains TeamCity antes de 2024.03, xXE era posible en el detector de pasos de compilación de Maven • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 5.5EPSS: 23%CPEs: 1EXPL: 0

28 Mar 2024 — In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings En JetBrains TeamCity antes de 2024.03, xSS era posible a través de la configuración de Distribución de agentes This vulnerability allows remote attackers to execute arbitrary script on affected installations of JetBrains TeamCity. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the os paramet... • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

28 Mar 2024 — In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration En JetBrains TeamCity antes de 2024.03 se reflejaba que XSS era posible a través de la configuración de conexión espacial • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.4EPSS: 0%CPEs: 1EXPL: 0

28 Mar 2024 — In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter En JetBrains TeamCity antes de 2024.03, 2FA se podía omitir proporcionando un parámetro de URL especial • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-1288: Improper Validation of Consistency within Input •