Jetbrains
jetbrains
564 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (564)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains YouTrack before 2025.2.86069,
2024.3.85077,
2025.1.86199 email spoofing via an administrative API was possible |
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible |
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions |
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible |
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible |
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible |
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API |
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page |
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible |
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning |
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab |
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible |
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs |
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces |
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation |
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible |
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible |