CVE-2024-36362
https://notcve.org/view.php?id=CVE-2024-36362
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible En JetBrains TeamCity antes de 2022.04.6, 2022.10.5, 2023.05.5, 2023.11.5, 2024.03.2 era posible path traversal permitiendo leer archivos del servidor • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-23: Relative Path Traversal •
CVE-2024-35302
https://notcve.org/view.php?id=CVE-2024-35302
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-35301
https://notcve.org/view.php?id=CVE-2024-35301
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-280: Improper Handling of Insufficient Permissions or Privileges •
CVE-2024-31140
https://notcve.org/view.php?id=CVE-2024-31140
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools En JetBrains TeamCity antes de 2024.03, los administradores del servidor podían eliminar archivos arbitrarios del servidor instalando herramientas • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-1288: Improper Validation of Consistency within Input •
CVE-2024-31139
https://notcve.org/view.php?id=CVE-2024-31139
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector En JetBrains TeamCity antes de 2024.03, xXE era posible en el detector de pasos de compilación de Maven • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-611: Improper Restriction of XML External Entity Reference •