← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 3, 2021
N/A· v4
3.8 LOW· v3
5.5 MEDIUM· v2
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 3, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
1Jetbrains
1Ktor
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
1Jetbrains
1Ktor
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
1Jetbrains
1Ktor
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
1Jetbrains
1Hub
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
1Jetbrains
1Hub
Nov 21, 2024
Feb 3, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
1Jetbrains
1Intellij Idea
Nov 21, 2024
Feb 3, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
1Jetbrains
1Hub
Nov 21, 2024
Feb 3, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
1Jetbrains
1Intellij Idea
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.