CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition |
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |
1Jetbrains 4Dottrace Etw Host ServiceResharper+1 moreJan 12, 2026 Jan 28, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation v...Show more |
1Jetbrains 13Aqua ClionDatagrip+10 moreNov 21, 2024 Jun 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4,...Show more |
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible |
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution |
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. |
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. |