← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Phpstorm
Jun 17, 2026
Apr 4, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
1Jetbrains
1Intellij Idea
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Mar 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Mar 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
1Jetbrains
1Hub
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 22, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 8, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system admi...Show more
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
1Jetbrains
1Jetbrains Gateway
Jun 17, 2026
Dec 8, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.