Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin |
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file |
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page |
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page |
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log |
In JetBrains GoLand before 2025.1 an XXE during debugging was possible |
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible |
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible |
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab |
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources |
1Jetbrains 4Dottrace Etw Host ServiceResharper+1 moreJan 12, 2026 Jan 28, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation v...Show more |
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint |
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool |
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page |
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration |
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs |
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping |
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack |
In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS |
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission |