← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Ktor
Nov 21, 2024
May 12, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
1Jetbrains
1Teamcity
Nov 21, 2024
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 12, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
1Jetbrains
1Teamcity
Nov 21, 2024
May 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
1Jetbrains
1Pycharm
Nov 21, 2024
Apr 28, 2022
N/A· v4
7.7 HIGH· v3
4.4 MEDIUM· v2
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
1Jetbrains
1Pycharm
Nov 21, 2024
Apr 28, 2022
N/A· v4
3.5 LOW· v3
3.3 LOW· v2
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
7.7 HIGH· v3
4.4 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
7.7 HIGH· v3
4.4 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 28, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
1Jetbrains
1Hub
Nov 21, 2024
Apr 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
1Jetbrains
1Ktor
Nov 21, 2024
Apr 11, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
1Jetbrains
1Intellij Idea
Nov 21, 2024
Apr 5, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
1Jetbrains
1Youtrack
Nov 21, 2024
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
1Jetbrains
1Youtrack
Nov 21, 2024
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
1Jetbrains
1Youtrack
Nov 21, 2024
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered