QID 379075
Date Published: 2023-12-26
QID 379075: JetBrains TeamCity Multiple Security Vulnerabilities (TW-82270,TW-82022,TW-81723,TW-81846,TW-81777,TW-80993,TW-80002)
JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.
CVE-2023-38061: Stored XSS when using a custom theme was possible (TW-82270).
CVE-2023-38062: Parameters of the "password" type could be shown in the UI in certain composite build configurations (TW-82022).
CVE-2023-38063: Stored XSS while running custom builds was possible.
CVE-2023-38064: Build chain parameters of the "password" type could be written to the agent log.
CVE-2023-38065: Stored XSS while viewing the build log was possible .
CVE-2023-38066: Reflected XSS via the Referer header was possible during artifact downloads.
CVE-2023-38067: Build parameters of the "password" type could be written to the agent log.
Affected Versions :
TeamCity prior to 2023.05.1
QID Detection Logic(Authenticated and Unauthenticated):
QID checks for vulnerable version of installed TeamCity in the System
Successful exploitation of this vulnerability may affect Confidentiality, Integrity and Availability of the data.
- JetBrains TeamCity -
www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity
CVEs related to QID 379075
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity |
|