QID 379549
Date Published: 2024-04-02
QID 379549: JetBrains TeamCity Multiple Security Vulnerabilities (TW-87046, TW-87062, TW-86989, TW-86832, TW-86535, TW-86300, TW-86039)
JetBrains TeamCity Server is a Java-based build management and continuous integration server from JetBrains.
CVE-2024-31134: Authenticated users without administrative permissions could register other users when self-registration was disabled.
CVE-2024-31135: Open redirect was possible on the login page.
CVE-2024-31136: 2FA could be bypassed by providing a special URL parameter.
CVE-2024-31137: Reflected XSS was possible via Space connection configuration.
CVE-2024-31138: XSS was possible via Agent Distribution settings.
CVE-2024-31139: XXE was possible in the Maven to build a steps detector.
CVE-2024-31140: Server administrators could remove arbitrary files from the server by installing tools.
Affected Versions:
JetBrains TeamCity prior to 2024.03
QID Detection Logic (Authenticated and Unauthenticated):
QID checks for vulnerable versions of installed TeamCity in the System.
Successful exploitation of this vulnerability may affect the Confidentiality, Integrity, and Availability of the data.
- JetBrains TeamCity -
www.jetbrains.com/privacy-security/issues-fixed/
CVEs related to QID 379549
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| JetBrains TeamCity |
|