Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2021
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
CVSS Score
6.1
EPSS Score
0.0
Published
2021-02-03
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
CVSS Score
4.3
EPSS Score
0.0
Published
2021-02-03
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
CVSS Score
3.8
EPSS Score
0.0
Published
2021-02-03
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
CVSS Score
7.5
EPSS Score
0.0
Published
2021-02-03
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
CVSS Score
5.3
EPSS Score
0.0
Published
2021-02-03
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
CVSS Score
5.3
EPSS Score
0.0
Published
2021-02-03
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
CVSS Score
9.8
EPSS Score
0.045
Published
2021-02-03
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
CVSS Score
5.4
EPSS Score
0.043
Published
2021-02-03
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
CVSS Score
7.5
EPSS Score
0.0
Published
2021-02-03
In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic.
CVSS Score
2.5
EPSS Score
0.0
Published
2021-02-03


Contact Us

Shodan ® - All rights reserved