CVE-2024-31136
https://notcve.org/view.php?id=CVE-2024-31136
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter En JetBrains TeamCity antes de 2024.03, 2FA se podía omitir proporcionando un parámetro de URL especial • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-1288: Improper Validation of Consistency within Input •
CVE-2024-31135
https://notcve.org/view.php?id=CVE-2024-31135
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page En JetBrains TeamCity antes de 2024.03, era posible abrir la redirección en la página de inicio de sesión • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2024-31134
https://notcve.org/view.php?id=CVE-2024-31134
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled En JetBrains TeamCity antes de 2024.03, los usuarios autenticados sin permisos administrativos podían registrar a otros usuarios cuando el registro automático estaba deshabilitado. • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-863: Incorrect Authorization •
CVE-2024-28174
https://notcve.org/view.php?id=CVE-2024-28174
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly En JetBrains TeamCity antes de 2023.11.4, las solicitudes de generación de URL prefirmadas en el complemento S3 Artifact Storage no se autorizaban correctamente • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-863: Incorrect Authorization •
CVE-2024-28173
https://notcve.org/view.php?id=CVE-2024-28173
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed En JetBrains TeamCity entre 2023.11 y 2023.11.4 se podrían revelar parámetros de compilación personalizados del tipo "contraseña" • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-201: Insertion of Sensitive Information Into Sent Data •