Vulnerabilities
Vulnerable Software
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
CVSS Score
5.3
EPSS Score
0.005
Published
2023-05-31
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
CVSS Score
5.3
EPSS Score
0.004
Published
2023-05-31
In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible
CVSS Score
4.6
EPSS Score
0.01
Published
2023-05-31
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
CVSS Score
4.6
EPSS Score
0.01
Published
2023-03-27
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVSS Score
4.6
EPSS Score
0.68
Published
2023-03-27
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVSS Score
5.2
EPSS Score
0.003
Published
2023-02-23
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVSS Score
5.4
EPSS Score
0.595
Published
2023-02-23
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVSS Score
5.4
EPSS Score
0.004
Published
2023-02-23
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVSS Score
4.1
EPSS Score
0.005
Published
2022-12-08
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVSS Score
6.6
EPSS Score
0.004
Published
2022-12-08


Contact Us

Shodan ® - All rights reserved