Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. |
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible. |
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie. |
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. |
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. |
2Jetbrains Oracle3Communications Cloud Native Core Binding Support Function Communications Pricing Design CenterKotlinNov 21, 2024 Feb 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. |
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. |
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. |
1Jetbrains 7Clion GolandIntellij Idea+4 moreNov 21, 2024 Feb 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CL...Show more |
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. |
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. |
In JetBrains Hub before 2021.1.13690, stored XSS is possible. |
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. |
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. |
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. |
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. |
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient. |
In JetBrains TeamCity before 2021.1.2, stored XSS is possible. |
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. |
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. |