← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
1Jetbrains
1Hub
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
1Jetbrains
1Hub
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
1Jetbrains
1Hub
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
1Jetbrains
1Intellij Idea
Nov 21, 2024
Feb 25, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.
1Jetbrains
1Intellij Idea
Nov 21, 2024
Feb 25, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.