Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made. |
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. |
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. |
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. |
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects. |
In JetBrains TeamCity before 2020.2.3, XSS was possible. |
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. |
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. |
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. |
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible. |
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible. |
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. |
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset. |
In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. |
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. |
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. |
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects. |
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly |
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. |
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. |