Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration |
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed |
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible |
In JetBrains Ktor before 2.3.5 server certificates were not verified |
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE |
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration |
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible |
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration |
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step |
In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration |
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions |
In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible |
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers |
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access |
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases |
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms |
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log |
In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads |
In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible |
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log |