← Back

Upsource

upsource

Vendor: Jetbrains • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Upsource
Nov 21, 2024
May 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
1Jetbrains
1Upsource
Nov 21, 2024
Aug 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
1Jetbrains
2Teamcity
Upsource
Nov 21, 2024
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
1Jetbrains
1Upsource
Nov 21, 2024
Oct 2, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
1Jetbrains
1Upsource
Nov 21, 2024
Oct 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.