← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Mar 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 28, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
1Jetbrains
1Youtrack
Dec 16, 2024
Mar 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
1Jetbrains
1Youtrack
Dec 16, 2024
Mar 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
1Jetbrains
1Youtrack
Dec 16, 2024
Mar 7, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 6, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
1Jetbrains
1Teamcity
Dec 16, 2024
Mar 6, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
1Jetbrains
1Teamcity
Apr 21, 2026
Mar 4, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
1Jetbrains
1Teamcity
Oct 24, 2025
Mar 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
1Jetbrains
1Toolbox
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
1Jetbrains
1Intellij Idea
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
1Jetbrains
1Intellij Idea
May 15, 2025
Feb 6, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
1Jetbrains
1Rider
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
1Jetbrains
1Youtrack
Nov 21, 2024
Jan 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible