← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
2Jetbrains
Oracle
3Communications Cloud Native Core Binding Support Function
Communications Pricing Design CenterKotlin
Nov 21, 2024
Feb 25, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
1Jetbrains
1Hub
Nov 21, 2024
Feb 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
1Jetbrains
1Hub
Nov 21, 2024
Feb 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
1Jetbrains
7Clion
GolandIntellij Idea+4 more
Nov 21, 2024
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CL...Show more
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.Show less
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
1Jetbrains
1Hub
Nov 21, 2024
Nov 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
1Jetbrains
1Hub
Nov 21, 2024
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
1Jetbrains
1Hub
Nov 21, 2024
Nov 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
1Jetbrains
1Ktor
Nov 21, 2024
Nov 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 9, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.