|
194901
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25777
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194902
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25776
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194903
|
3.8 |
LOW
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
|
NVD-CWE-noinfo
|
CVE-2021-25775
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194904
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25774
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194905
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25773
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194906
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
|
NVD-CWE-noinfo
|
CVE-2021-25772
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194907
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
|
NVD-CWE-noinfo
|
CVE-2021-25771
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194908
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
|
CWE-94
Code Injection
|
CVE-2021-25770
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194909
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
|
NVD-CWE-noinfo
|
CVE-2021-25769
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194910
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
|
NVD-CWE-Other
|
CVE-2021-25768
|
2024-11-21 14:55 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|