← Back

Jetbrains

jetbrains

564 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Rider
rider
Kotlin
kotlin
Upsource
upsource
Webstorm
webstorm
Resharper
resharper
Goland
goland
Phpstorm
phpstorm
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (564)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Nov 21, 2024
Aug 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
1Jetbrains
1Teamcity
Nov 21, 2024
Aug 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
1Jetbrains
1Teamcity
Nov 21, 2024
Aug 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
1Jetbrains
1Teamcity
Nov 21, 2024
Aug 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
1Jetbrains
1Toolbox
Nov 21, 2024
Aug 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
1Jetbrains
1Teamcity
Nov 21, 2024
Aug 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
1Jetbrains
1Teamcity
Nov 21, 2024
Aug 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
2Jetbrains
Oracle
3Banking Extensibility Workbench
Communications Cloud Native Core PolicyKotlin
Nov 21, 2024
Aug 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the sy...Show more
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.Show less
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
1Jetbrains
1Youtrack
Nov 21, 2024
Aug 8, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
1Jetbrains
1Upsource
Nov 21, 2024
Aug 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
1Jetbrains
1Teamcity
Nov 21, 2024
Apr 22, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
1Jetbrains
1Space
Nov 21, 2024
Apr 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
1Jetbrains
1Space
Nov 21, 2024
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
1Jetbrains
1Youtrack
Nov 21, 2024
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
1Jetbrains
1Youtrack
Nov 21, 2024
Apr 22, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.