Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. |
In JetBrains TeamCity before 2021.1.2, user enumeration was possible. |
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. |
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. |
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. |
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. |
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. |
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. |
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. |
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. |
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. |
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. |
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. |
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. |
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. |
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. |
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. |
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. |
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. |
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS. |