CVE-2024-35301
https://notcve.org/view.php?id=CVE-2024-35301
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-280: Improper Handling of Insufficient Permissions or Privileges •
CVE-2024-31140
https://notcve.org/view.php?id=CVE-2024-31140
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools En JetBrains TeamCity antes de 2024.03, los administradores del servidor podían eliminar archivos arbitrarios del servidor instalando herramientas • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-1288: Improper Validation of Consistency within Input •
CVE-2024-31139
https://notcve.org/view.php?id=CVE-2024-31139
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector En JetBrains TeamCity antes de 2024.03, xXE era posible en el detector de pasos de compilación de Maven • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2024-31138 – JetBrains TeamCity AgentDistributionSettingsController Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2024-31138
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings En JetBrains TeamCity antes de 2024.03, xSS era posible a través de la configuración de Distribución de agentes This vulnerability allows remote attackers to execute arbitrary script on affected installations of JetBrains TeamCity. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the os parameter provided to the AgentDistributionSettingsController.doPost method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of arbitrary script. An attacker can leverage this vulnerability to execute script in the context of the current user. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-31137
https://notcve.org/view.php?id=CVE-2024-31137
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration En JetBrains TeamCity antes de 2024.03 se reflejaba que XSS era posible a través de la configuración de conexión espacial • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •