|
223241
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-12852
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223242
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
|
NVD-CWE-noinfo
|
CVE-2019-12846
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223243
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
|
CWE-287
Improper Authentication
|
CVE-2019-12845
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223244
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.
|
CWE-94
Code Injection
|
CVE-2019-12844
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223245
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.
|
CWE-94
Code Injection
|
CVE-2019-12843
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223246
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12842
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223247
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
|
CWE-20
Improper Input Validation
|
CVE-2019-12841
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223248
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
|
NVD-CWE-noinfo
|
CVE-2019-12867
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223249
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-12866
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223250
|
8.8 |
HIGH
Network
|
jetbrains
|
youtrack
|
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
|
CWE-352
Origin Validation Error
|
CVE-2019-12851
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|