Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible. |
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases. |
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file. |
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. |
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. |
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings. |
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. |
JetBrains Space through 2020-04-22 allows stored XSS in Chats. |
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. |
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. |
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3. |
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. |
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. |
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. |
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. |
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. |
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages. |
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. |
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. |
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. |