← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
1Jetbrains
1Youtrack
Jun 17, 2026
Mar 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
1Jetbrains
1Youtrack
Jun 17, 2026
Mar 7, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
1Jetbrains
1Youtrack
Jun 17, 2026
Mar 7, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 6, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 6, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 4, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
1Jetbrains
1Toolbox
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
1Jetbrains
1Intellij Idea
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
1Jetbrains
1Intellij Idea
Jun 17, 2026
Feb 6, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
1Jetbrains
1Rider
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 6, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
1Jetbrains
1Youtrack
Jun 17, 2026
Jan 9, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed