← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Code With Me
Nov 21, 2024
Feb 3, 2021
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic.
1Jetbrains
1Teamcity
Nov 21, 2024
Feb 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
2Jetbrains
Oracle
4Communications Cloud Native Core Network Slice Selection Function
Communications Cloud Native Core PolicyCommunications Cloud Native Core Service Communication Proxy+1 more
Feb 25, 2026
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
1Jetbrains
1Youtrack
Nov 21, 2024
Feb 3, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 16, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
1Jetbrains
1Ideavim
Nov 21, 2024
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
1Jetbrains
1Intellij Idea
Nov 21, 2024
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
1Jetbrains
1Ktor
Nov 21, 2024
Nov 16, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
1Jetbrains
1Teamcity
Nov 21, 2024
Nov 16, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
1Jetbrains
1Youtrack
Nov 21, 2024
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
1Jetbrains
1Youtrack
Nov 21, 2024
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
1Jetbrains
1Youtrack
Nov 21, 2024
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
1Jetbrains
1Youtrack
Nov 21, 2024
Nov 16, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
1Jetbrains
1Youtrack
Nov 21, 2024
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
1Jetbrains
1Toolbox
Nov 21, 2024
Nov 16, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
1Jetbrains
1Toolbox
Nov 21, 2024
Nov 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
1Jetbrains
1Youtrack
Nov 21, 2024
Nov 16, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
1Jetbrains
1Youtrack
Nov 21, 2024
Oct 19, 2020
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 27, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.