← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jan 27, 2025
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
1Jetbrains
1Teamcity
Feb 7, 2025
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 29, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
1Jetbrains
1Teamcity
Dec 16, 2024
May 16, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
1Jetbrains
1Teamcity
Dec 16, 2024
May 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
1Jetbrains
1Youtrack
Jan 28, 2025
May 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 28, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter