|
223411
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
|
CWE-287
Improper Authentication
|
CVE-2019-12845
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223412
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
|
CWE-94
Code Injection
|
CVE-2019-12844
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223413
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
|
CWE-94
Code Injection
|
CVE-2019-12843
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223414
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12842
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223415
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
|
CWE-20
Improper Input Validation
|
CVE-2019-12841
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223416
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
|
NVD-CWE-noinfo
|
CVE-2019-12867
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223417
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-12866
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223418
|
8.8 |
HIGH
Network
|
jetbrains
|
youtrack
|
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
|
CWE-352
Origin Validation Error
|
CVE-2019-12851
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223419
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.
|
CWE-89
SQL Injection
|
CVE-2019-12850
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223420
|
7.2 |
HIGH
Network
|
jetbrains
|
hub
|
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-12847
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|