← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 22, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 22, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 22, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
1Jetbrains
1Teamcity
Nov 21, 2024
Jul 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
1Jetbrains
1Hub
Nov 21, 2024
Jun 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
1Jetbrains
1Youtrack
Nov 21, 2024
Jun 18, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
1Jetbrains
1Youtrack
Nov 21, 2024
Jun 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
1Jetbrains
1Youtrack
Nov 21, 2024
Jun 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
1Jetbrains
13Aqua
ClionDatagrip+10 more
Nov 21, 2024
Jun 10, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4,...Show more
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4Show less
1Jetbrains
1Teamcity
Feb 7, 2025
May 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible