QID 379161
Date Published: 2023-12-26
QID 379161: JetBrains TeamCity Multiple Security Vulnerabilities (TW-73518,TW-76796,TW-77048,TW-75537)
JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.
CVE-2022-44622: Excessive access permissions for secure token health items.
CVE-2022-44623: Project Viewer could see scrambled secure values in the MetaRunner settings.
CVE-2022-44624 :Password parameters could be exposed in the build log if they contained special characters.
CVE-2022-44646: No audit items were added upon editing a user's settings.
Affected Versions :
TeamCity prior to 2022.10
QID Detection Logic (Authenticated and Unauthenticated):
QID checks for vulnerable version of installed TeamCity in the System
Successful exploitation of this vulnerability may affect Confidentiality, Integrity, and Availability of the data.
- JetBrains TeamCity -
www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity
CVEs related to QID 379161
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity |
|