QID 375387
Date Published: 2021-03-23
QID 375387: JetBrains TeamCity Multiple Vulnrabilities
JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.
Multiple issues discovered in TeamCity
CVE-2019-15042 VMWare plugin did not check SSL certificate. (TW-59562)
CVE-2019-15039 Remote Code Execution on the server with certain network configurations. (TW-60430)
CVE-2019-15035 Project administrator could get unauthorized access to server-level data. (TW-60220)
CVE-2019-15036 Project administrator could execute any command on the server machine. (TW-60219)
CVE-2019-15038 Security has been tightened thanks to using additional HTTP headers. (TW-59034)
CVE-2019-15037 Possible XSS vulnerabilities on the settings pages. (TW-59870, TW-59852, TW-59817, TW-59838, TW-59816)
CVE-2019-15848 XSS vulnerability. (TW-61242, TW-61315)
Affected Versions :
JetBrains TeamCity 2018.2.4
QID Detection Logic(Authenticated)
This checks for vulnerable version of TeamCity.
On successful exploitation it allows possible remote code execution.
Update to the latest version of JetBrains TeamCity.
- JetBrains TeamCity -
blog.jetbrains.com/blog/2019/09/26/jetbrains-security-bulletin-q2-2019/
CVEs related to QID 375387
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity | Linux |
|