CVE Vulnerabilities

CVE-2022-25264

Insecure Storage of Sensitive Information

Published: Feb 25, 2022 | Modified: Mar 08, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In JetBrains TeamCity before 2021.2.3, environment variables of the password type could be logged in some cases.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Teamcity Jetbrains * 2021.2.3 (excluding)

References