← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
1Jetbrains
1Teamcity
Jan 2, 2025
Dec 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
1Jetbrains
1Youtrack
Jan 30, 2025
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
1Jetbrains
1Youtrack
Jan 30, 2025
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
1Jetbrains
1Youtrack
Jan 30, 2025
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
1Jetbrains
1Youtrack
Jan 31, 2025
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
1Jetbrains
1Youtrack
Jan 31, 2025
Dec 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
1Jetbrains
1Youtrack
Jan 31, 2025
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
1Jetbrains
1Webstorm
Jan 31, 2025
Nov 15, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
1Jetbrains
1Youtrack
Oct 29, 2024
Oct 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest