← Back

Jetbrains

jetbrains

602 CVEs • 38 products

Products (38)

Click to collapse
Toggle
Teamcity
teamcity
Youtrack
youtrack
Intellij Idea
intellij_idea
Hub
hub
Ktor
ktor
Toolbox
toolbox
Pycharm
pycharm
Webstorm
webstorm
Rider
rider
Goland
goland
Kotlin
kotlin
Phpstorm
phpstorm
Upsource
upsource
Resharper
resharper
Rubymine
rubymine
Space
space
Code With Me
code_with_me
Junie
junie
Mps
mps
Clion
clion
Dottrace
dottrace
Dotpeek
dotpeek
Vim
vim
Idetalk
idetalk
Scala
scala
Ideavim
ideavim
Aqua
aqua
Datagrip
datagrip
Dataspell
dataspell
Rustrover
rustrover
Runtime
runtime
Ide Services
ide_services
Datalore
datalore

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
1Jetbrains
1Teamcity
Jun 17, 2026
Apr 22, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
1Jetbrains
1Goland
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
1Jetbrains
1Space
Jun 17, 2026
Apr 22, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
1Jetbrains
1Pycharm
Jun 17, 2026
Apr 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
1Jetbrains
1Scala
Jun 17, 2026
Feb 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.
1Jetbrains
1Youtrack
Jun 17, 2026
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
1Jetbrains
1Youtrack
Jun 17, 2026
Jan 30, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
1Jetbrains
1Rider
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
1Jetbrains
1Ktor
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
1Jetbrains
1Idetalk
Jun 17, 2026
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JetBrains IDETalk plugin before version 193.4099.10 allows XXE