Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page |
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration |
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload |
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute |
In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata |
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure |
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit |
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure |
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form |
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API |
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit |
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations |
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition |
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation |
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command...Show more |
In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows |
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload |
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition |
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_proj...Show more |
In JetBrains IDE Services before 2025.5.0.1086,
2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves |