jetbrains CVE Vulnerabilities & Metrics

Focus on jetbrains vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About jetbrains Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with jetbrains. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total jetbrains CVEs: 437
Earliest CVE date: 13 Jan 2015, 11:59 UTC
Latest CVE date: 21 Jan 2025, 18:15 UTC

Latest CVE reference: CVE-2025-24461

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 92

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 35.29%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 35.29%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical jetbrains CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.93

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 211
4.0-6.9 192
7.0-8.9 31
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS jetbrains CVEs

These are the five CVEs with the highest CVSS scores for jetbrains, sorted by severity first and recency.

All CVEs for jetbrains

CVE-2025-24461 jetbrains vulnerability CVSS: 0 21 Jan 2025, 18:15 UTC

In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint

CVE-2025-24460 jetbrains vulnerability CVSS: 0 21 Jan 2025, 18:15 UTC

In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool

CVE-2025-24459 jetbrains vulnerability CVSS: 0 21 Jan 2025, 18:15 UTC

In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page

CVE-2025-24458 jetbrains vulnerability CVSS: 0 21 Jan 2025, 18:15 UTC

In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

CVE-2025-24457 jetbrains vulnerability CVSS: 0 21 Jan 2025, 18:15 UTC

In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

CVE-2025-24456 jetbrains vulnerability CVSS: 0 21 Jan 2025, 18:15 UTC

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

CVE-2024-56356 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

CVE-2024-56355 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS

CVE-2024-56354 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission

CVE-2024-56353 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies

CVE-2024-56352 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details page

CVE-2024-56351 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

CVE-2024-56350 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

CVE-2024-56349 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs

CVE-2024-56348 jetbrains vulnerability CVSS: 0 20 Dec 2024, 15:15 UTC

In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

CVE-2024-54158 jetbrains vulnerability CVSS: 0 04 Dec 2024, 12:15 UTC

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

CVE-2024-54157 jetbrains vulnerability CVSS: 0 04 Dec 2024, 12:15 UTC

In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

CVE-2024-54156 jetbrains vulnerability CVSS: 0 04 Dec 2024, 12:15 UTC

In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

CVE-2024-54155 jetbrains vulnerability CVSS: 0 04 Dec 2024, 12:15 UTC

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

CVE-2024-54154 jetbrains vulnerability CVSS: 0 04 Dec 2024, 12:15 UTC

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

CVE-2024-54153 jetbrains vulnerability CVSS: 0 04 Dec 2024, 12:15 UTC

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

CVE-2024-52555 jetbrains vulnerability CVSS: 0 15 Nov 2024, 16:15 UTC

In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

CVE-2024-50582 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

CVE-2024-50581 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

CVE-2024-50580 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

CVE-2024-50579 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

CVE-2024-50578 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

CVE-2024-50577 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

CVE-2024-50576 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

CVE-2024-50575 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

CVE-2024-50574 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

CVE-2024-50573 jetbrains vulnerability CVSS: 0 28 Oct 2024, 13:15 UTC

In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

CVE-2024-49580 jetbrains vulnerability CVSS: 0 17 Oct 2024, 13:15 UTC

In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

CVE-2024-49579 jetbrains vulnerability CVSS: 0 17 Oct 2024, 13:15 UTC

In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

CVE-2024-48902 jetbrains vulnerability CVSS: 0 10 Oct 2024, 11:15 UTC

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

CVE-2024-47951 jetbrains vulnerability CVSS: 0 08 Oct 2024, 16:15 UTC

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

CVE-2024-47950 jetbrains vulnerability CVSS: 0 08 Oct 2024, 16:15 UTC

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

CVE-2024-47949 jetbrains vulnerability CVSS: 0 08 Oct 2024, 16:15 UTC

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

CVE-2024-47948 jetbrains vulnerability CVSS: 0 08 Oct 2024, 16:15 UTC

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

CVE-2024-47161 jetbrains vulnerability CVSS: 0 08 Oct 2024, 16:15 UTC

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

CVE-2024-47162 jetbrains vulnerability CVSS: 0 19 Sep 2024, 18:15 UTC

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

CVE-2024-47160 jetbrains vulnerability CVSS: 0 19 Sep 2024, 18:15 UTC

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

CVE-2024-47159 jetbrains vulnerability CVSS: 0 19 Sep 2024, 18:15 UTC

In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

CVE-2024-46970 jetbrains vulnerability CVSS: 0 16 Sep 2024, 11:15 UTC

In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

CVE-2024-43810 jetbrains vulnerability CVSS: 0 16 Aug 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin

CVE-2024-43809 jetbrains vulnerability CVSS: 0 16 Aug 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page

CVE-2024-43808 jetbrains vulnerability CVSS: 0 16 Aug 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin

CVE-2024-43807 jetbrains vulnerability CVSS: 0 16 Aug 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page

CVE-2024-43114 jetbrains vulnerability CVSS: 0 06 Aug 2024, 13:15 UTC

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

CVE-2024-41829 jetbrains vulnerability CVSS: 0 22 Jul 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

CVE-2024-41828 jetbrains vulnerability CVSS: 0 22 Jul 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

CVE-2024-41827 jetbrains vulnerability CVSS: 0 22 Jul 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

CVE-2024-41826 jetbrains vulnerability CVSS: 0 22 Jul 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

CVE-2024-41825 jetbrains vulnerability CVSS: 0 22 Jul 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

CVE-2024-41824 jetbrains vulnerability CVSS: 0 22 Jul 2024, 15:15 UTC

In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

CVE-2024-39879 jetbrains vulnerability CVSS: 0 01 Jul 2024, 17:15 UTC

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

CVE-2024-39878 jetbrains vulnerability CVSS: 0 01 Jul 2024, 17:15 UTC

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

CVE-2024-38507 jetbrains vulnerability CVSS: 0 18 Jun 2024, 11:15 UTC

In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible

CVE-2024-38506 jetbrains vulnerability CVSS: 0 18 Jun 2024, 11:15 UTC

In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

CVE-2024-38505 jetbrains vulnerability CVSS: 0 18 Jun 2024, 11:15 UTC

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

CVE-2024-38504 jetbrains vulnerability CVSS: 0 18 Jun 2024, 11:15 UTC

In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

CVE-2024-37051 jetbrains vulnerability CVSS: 0 10 Jun 2024, 16:15 UTC

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

CVE-2024-36470 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

CVE-2024-36378 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens

CVE-2024-36377 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions

CVE-2024-36376 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissions

CVE-2024-36375 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed

CVE-2024-36374 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible

CVE-2024-36373 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible

CVE-2024-36372 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible

CVE-2024-36371 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible

CVE-2024-36370 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possible

CVE-2024-36369 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possible

CVE-2024-36368 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possible

CVE-2024-36367 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possible

CVE-2024-36366 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering operations

CVE-2024-36365 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent

CVE-2024-36364 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible

CVE-2024-36363 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possible

CVE-2024-36362 jetbrains vulnerability CVSS: 0 29 May 2024, 14:15 UTC

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

CVE-2024-35302 jetbrains vulnerability CVSS: 0 16 May 2024, 11:15 UTC

In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible

CVE-2024-35301 jetbrains vulnerability CVSS: 0 16 May 2024, 11:15 UTC

In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

CVE-2024-35300 jetbrains vulnerability CVSS: 0 16 May 2024, 11:15 UTC

In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible

CVE-2024-35299 jetbrains vulnerability CVSS: 0 16 May 2024, 11:15 UTC

In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

CVE-2024-31140 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

CVE-2024-31139 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

CVE-2024-31138 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

CVE-2024-31137 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

CVE-2024-31136 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

CVE-2024-31135 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

CVE-2024-31134 jetbrains vulnerability CVSS: 0 28 Mar 2024, 15:15 UTC

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

CVE-2024-29880 jetbrains vulnerability CVSS: 0 21 Mar 2024, 14:15 UTC

In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

CVE-2024-28230 jetbrains vulnerability CVSS: 0 07 Mar 2024, 12:15 UTC

In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

CVE-2024-28229 jetbrains vulnerability CVSS: 0 07 Mar 2024, 12:15 UTC

In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

CVE-2024-28228 jetbrains vulnerability CVSS: 0 07 Mar 2024, 12:15 UTC

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

CVE-2024-28174 jetbrains vulnerability CVSS: 0 06 Mar 2024, 17:15 UTC

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

CVE-2024-28173 jetbrains vulnerability CVSS: 0 06 Mar 2024, 17:15 UTC

In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

CVE-2024-27199 jetbrains vulnerability CVSS: 0 04 Mar 2024, 18:15 UTC

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVE-2024-27198 jetbrains vulnerability CVSS: 0 04 Mar 2024, 18:15 UTC

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVE-2024-24943 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

CVE-2024-24942 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

CVE-2024-24941 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

CVE-2024-24940 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

CVE-2024-24939 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

CVE-2024-24938 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

CVE-2024-24937 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

CVE-2024-24936 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

CVE-2024-23917 jetbrains vulnerability CVSS: 0 06 Feb 2024, 10:15 UTC

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

CVE-2024-22370 jetbrains vulnerability CVSS: 0 09 Jan 2024, 10:15 UTC

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

CVE-2023-51655 jetbrains vulnerability CVSS: 0 21 Dec 2023, 10:15 UTC

In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

CVE-2023-50871 jetbrains vulnerability CVSS: 0 15 Dec 2023, 14:15 UTC

In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

CVE-2023-50870 jetbrains vulnerability CVSS: 0 15 Dec 2023, 14:15 UTC

In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible

CVE-2023-45613 jetbrains vulnerability CVSS: 0 09 Oct 2023, 11:15 UTC

In JetBrains Ktor before 2.3.5 server certificates were not verified

CVE-2023-45612 jetbrains vulnerability CVSS: 0 09 Oct 2023, 11:15 UTC

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

CVE-2023-43566 jetbrains vulnerability CVSS: 0 19 Sep 2023, 17:15 UTC

In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration

CVE-2023-42793 jetbrains vulnerability CVSS: 0 19 Sep 2023, 17:15 UTC

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

CVE-2023-41250 jetbrains vulnerability CVSS: 0 25 Aug 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration

CVE-2023-41249 jetbrains vulnerability CVSS: 0 25 Aug 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

CVE-2023-41248 jetbrains vulnerability CVSS: 0 25 Aug 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration

CVE-2023-39261 jetbrains vulnerability CVSS: 0 26 Jul 2023, 13:15 UTC

In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions

CVE-2023-39175 jetbrains vulnerability CVSS: 0 25 Jul 2023, 15:15 UTC

In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible

CVE-2023-39174 jetbrains vulnerability CVSS: 0 25 Jul 2023, 15:15 UTC

In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

CVE-2023-39173 jetbrains vulnerability CVSS: 0 25 Jul 2023, 15:15 UTC

In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access

CVE-2023-38069 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases

CVE-2023-38068 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

CVE-2023-38067 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

CVE-2023-38066 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 reflected XSS via the Referer header was possible during artifact downloads

CVE-2023-38065 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possible

CVE-2023-38064 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

CVE-2023-38063 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possible

CVE-2023-38062 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

CVE-2023-38061 jetbrains vulnerability CVSS: 0 12 Jul 2023, 13:15 UTC

In JetBrains TeamCity before 2023.05.1 stored XSS when using a custom theme was possible

CVE-2015-1313 jetbrains vulnerability CVSS: 0 29 Jun 2023, 15:15 UTC

JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that are returned to the web browser after an initial unauthenticated request.

CVE-2023-35054 jetbrains vulnerability CVSS: 0 12 Jun 2023, 16:15 UTC

In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible

CVE-2023-35053 jetbrains vulnerability CVSS: 0 12 Jun 2023, 16:15 UTC

In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms

CVE-2023-34339 jetbrains vulnerability CVSS: 0 01 Jun 2023, 19:15 UTC

In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message

CVE-2023-34229 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible

CVE-2023-34228 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions

CVE-2023-34227 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks

CVE-2023-34226 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible

CVE-2023-34225 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible

CVE-2023-34224 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible

CVE-2023-34223 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

CVE-2023-34222 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible

CVE-2023-34221 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible

CVE-2023-34220 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible

CVE-2023-34219 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

CVE-2023-34218 jetbrains vulnerability CVSS: 0 31 May 2023, 14:15 UTC

In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible

CVE-2022-48481 jetbrains vulnerability CVSS: 0 28 Apr 2023, 10:15 UTC

In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible

CVE-2022-48477 jetbrains vulnerability CVSS: 0 24 Apr 2023, 13:15 UTC

In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing

CVE-2022-48476 jetbrains vulnerability CVSS: 0 24 Apr 2023, 13:15 UTC

In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible

CVE-2022-48435 jetbrains vulnerability CVSS: 0 04 Apr 2023, 14:15 UTC

In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file

CVE-2022-48433 jetbrains vulnerability CVSS: 0 29 Mar 2023, 13:15 UTC

In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.

CVE-2022-48432 jetbrains vulnerability CVSS: 0 29 Mar 2023, 13:15 UTC

In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.

CVE-2022-48431 jetbrains vulnerability CVSS: 0 29 Mar 2023, 13:15 UTC

In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.

CVE-2022-48430 jetbrains vulnerability CVSS: 0 29 Mar 2023, 13:15 UTC

In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.

CVE-2022-48428 jetbrains vulnerability CVSS: 0 27 Mar 2023, 17:15 UTC

In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible

CVE-2022-48427 jetbrains vulnerability CVSS: 0 27 Mar 2023, 17:15 UTC

In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible

CVE-2022-48429 jetbrains vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVE-2022-48426 jetbrains vulnerability CVSS: 0 27 Mar 2023, 16:15 UTC

In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible

CVE-2022-48344 jetbrains vulnerability CVSS: 0 23 Feb 2023, 16:15 UTC

In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.

CVE-2022-48343 jetbrains vulnerability CVSS: 0 23 Feb 2023, 16:15 UTC

In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.

CVE-2022-48342 jetbrains vulnerability CVSS: 0 23 Feb 2023, 16:15 UTC

In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

CVE-2022-47896 jetbrains vulnerability CVSS: 0 22 Dec 2022, 11:15 UTC

In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.

CVE-2022-47895 jetbrains vulnerability CVSS: 0 22 Dec 2022, 11:15 UTC

In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.

CVE-2022-46831 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.

CVE-2022-46830 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.

CVE-2022-46828 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.

CVE-2022-46827 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.

CVE-2022-46826 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.

CVE-2022-46825 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.

CVE-2022-46824 jetbrains vulnerability CVSS: 0 08 Dec 2022, 18:15 UTC

In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.

CVE-2022-45471 jetbrains vulnerability CVSS: 0 18 Nov 2022, 15:15 UTC

In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

CVE-2022-44646 jetbrains vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings

CVE-2022-44624 jetbrains vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters

CVE-2022-44623 jetbrains vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings

CVE-2022-44622 jetbrains vulnerability CVSS: 0 03 Nov 2022, 14:15 UTC

In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive

CVE-2022-40979 jetbrains vulnerability CVSS: 0 23 Sep 2022, 11:15 UTC

In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable

CVE-2022-40978 jetbrains vulnerability CVSS: 0 19 Sep 2022, 16:15 UTC

The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking

CVE-2022-38180 jetbrains vulnerability CVSS: 0 12 Aug 2022, 10:15 UTC

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

CVE-2022-38179 jetbrains vulnerability CVSS: 0 12 Aug 2022, 10:15 UTC

JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack

CVE-2022-38133 jetbrains vulnerability CVSS: 0 10 Aug 2022, 16:15 UTC

In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

CVE-2022-37396 jetbrains vulnerability CVSS: 0 03 Aug 2022, 16:15 UTC

In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution

CVE-2022-37010 jetbrains vulnerability CVSS: 0 28 Jul 2022, 11:15 UTC

In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed

CVE-2022-37009 jetbrains vulnerability CVSS: 0 28 Jul 2022, 11:15 UTC

In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible

CVE-2022-36322 jetbrains vulnerability CVSS: 0 20 Jul 2022, 13:15 UTC

In JetBrains TeamCity before 2022.04.2 build parameter injection was possible

CVE-2022-36321 jetbrains vulnerability CVSS: 0 20 Jul 2022, 13:15 UTC

In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases

CVE-2022-34894 jetbrains vulnerability CVSS: 5.0 01 Jul 2022, 10:15 UTC

In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

CVE-2022-29930 jetbrains vulnerability CVSS: 4.0 12 May 2022, 09:15 UTC

SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

CVE-2022-29929 jetbrains vulnerability CVSS: 4.3 12 May 2022, 09:15 UTC

In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible

CVE-2022-29928 jetbrains vulnerability CVSS: 4.0 12 May 2022, 09:15 UTC

In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible

CVE-2022-29927 jetbrains vulnerability CVSS: 4.3 12 May 2022, 09:15 UTC

In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible

CVE-2022-29821 jetbrains vulnerability CVSS: 4.4 28 Apr 2022, 10:15 UTC

In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

CVE-2022-29820 jetbrains vulnerability CVSS: 3.3 28 Apr 2022, 10:15 UTC

In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible

CVE-2022-29819 jetbrains vulnerability CVSS: 4.4 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

CVE-2022-29818 jetbrains vulnerability CVSS: 3.6 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed

CVE-2022-29817 jetbrains vulnerability CVSS: 4.3 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible

CVE-2022-29816 jetbrains vulnerability CVSS: 2.1 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible

CVE-2022-29815 jetbrains vulnerability CVSS: 4.6 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

CVE-2022-29814 jetbrains vulnerability CVSS: 4.4 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

CVE-2022-29813 jetbrains vulnerability CVSS: 4.6 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

CVE-2022-29812 jetbrains vulnerability CVSS: 2.1 28 Apr 2022, 10:15 UTC

In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient

CVE-2022-29811 jetbrains vulnerability CVSS: 3.5 28 Apr 2022, 10:15 UTC

In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.

CVE-2022-29035 jetbrains vulnerability CVSS: 4.0 11 Apr 2022, 19:15 UTC

In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

CVE-2022-28651 jetbrains vulnerability CVSS: 2.1 05 Apr 2022, 18:15 UTC

In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

CVE-2022-28650 jetbrains vulnerability CVSS: 3.5 05 Apr 2022, 18:15 UTC

In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

CVE-2022-28649 jetbrains vulnerability CVSS: 3.5 05 Apr 2022, 18:15 UTC

In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

CVE-2022-28648 jetbrains vulnerability CVSS: 3.5 05 Apr 2022, 18:15 UTC

In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered

CVE-2022-25264 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 20:15 UTC

In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

CVE-2022-25263 jetbrains vulnerability CVSS: 7.5 25 Feb 2022, 20:15 UTC

JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.

CVE-2022-25262 jetbrains vulnerability CVSS: 7.5 25 Feb 2022, 20:15 UTC

In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

CVE-2022-25261 jetbrains vulnerability CVSS: 4.3 25 Feb 2022, 20:15 UTC

JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.

CVE-2022-25260 jetbrains vulnerability CVSS: 6.4 25 Feb 2022, 20:15 UTC

JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

CVE-2022-25259 jetbrains vulnerability CVSS: 4.3 25 Feb 2022, 20:15 UTC

JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.

CVE-2022-24442 jetbrains vulnerability CVSS: 7.5 25 Feb 2022, 20:15 UTC

JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

CVE-2022-24347 jetbrains vulnerability CVSS: 3.5 25 Feb 2022, 15:15 UTC

JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

CVE-2022-24346 jetbrains vulnerability CVSS: 4.6 25 Feb 2022, 15:15 UTC

In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

CVE-2022-24345 jetbrains vulnerability CVSS: 4.6 25 Feb 2022, 15:15 UTC

In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

CVE-2022-24344 jetbrains vulnerability CVSS: 3.5 25 Feb 2022, 15:15 UTC

JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

CVE-2022-24343 jetbrains vulnerability CVSS: 4.0 25 Feb 2022, 15:15 UTC

In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

CVE-2022-24342 jetbrains vulnerability CVSS: 6.8 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

CVE-2022-24341 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

CVE-2022-24340 jetbrains vulnerability CVSS: 7.5 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

CVE-2022-24339 jetbrains vulnerability CVSS: 3.5 25 Feb 2022, 15:15 UTC

JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.

CVE-2022-24338 jetbrains vulnerability CVSS: 4.3 25 Feb 2022, 15:15 UTC

JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.

CVE-2022-24337 jetbrains vulnerability CVSS: 4.0 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

CVE-2022-24336 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.

CVE-2022-24335 jetbrains vulnerability CVSS: 6.8 25 Feb 2022, 15:15 UTC

JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.

CVE-2022-24334 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

CVE-2022-24333 jetbrains vulnerability CVSS: 4.0 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

CVE-2022-24332 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

CVE-2022-24331 jetbrains vulnerability CVSS: 7.5 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

CVE-2022-24330 jetbrains vulnerability CVSS: 5.8 25 Feb 2022, 15:15 UTC

In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.

CVE-2022-24329 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 15:15 UTC

In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

CVE-2022-24328 jetbrains vulnerability CVSS: 4.0 25 Feb 2022, 15:15 UTC

In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.

CVE-2022-24327 jetbrains vulnerability CVSS: 5.0 25 Feb 2022, 15:15 UTC

In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

CVE-2021-45977 jetbrains vulnerability CVSS: 7.5 25 Feb 2022, 15:15 UTC

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

CVE-2021-43202 jetbrains vulnerability CVSS: 7.5 30 Nov 2021, 16:15 UTC

In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.

CVE-2021-43182 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 16:15 UTC

In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.

CVE-2021-43181 jetbrains vulnerability CVSS: 4.3 09 Nov 2021, 16:15 UTC

In JetBrains Hub before 2021.1.13690, stored XSS is possible.

CVE-2021-43180 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 16:15 UTC

In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.

CVE-2021-43203 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 15:15 UTC

In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.

CVE-2021-43201 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

CVE-2021-43200 jetbrains vulnerability CVSS: 7.5 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.

CVE-2021-43199 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

CVE-2021-43198 jetbrains vulnerability CVSS: 3.5 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, stored XSS is possible.

CVE-2021-43197 jetbrains vulnerability CVSS: 4.3 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.

CVE-2021-43196 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

CVE-2021-43195 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.

CVE-2021-43194 jetbrains vulnerability CVSS: 5.0 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

CVE-2021-43193 jetbrains vulnerability CVSS: 7.5 09 Nov 2021, 15:15 UTC

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

CVE-2021-43186 jetbrains vulnerability CVSS: 3.5 09 Nov 2021, 15:15 UTC

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

CVE-2021-43185 jetbrains vulnerability CVSS: 7.5 09 Nov 2021, 15:15 UTC

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

CVE-2021-43184 jetbrains vulnerability CVSS: 3.5 09 Nov 2021, 15:15 UTC

In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.

CVE-2021-43183 jetbrains vulnerability CVSS: 7.5 09 Nov 2021, 15:15 UTC

In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

CVE-2021-37554 jetbrains vulnerability CVSS: 4.0 06 Aug 2021, 14:15 UTC

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVE-2021-37553 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

CVE-2021-37552 jetbrains vulnerability CVSS: 3.5 06 Aug 2021, 14:15 UTC

In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.

CVE-2021-37551 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVE-2021-37550 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

CVE-2021-37549 jetbrains vulnerability CVSS: 6.4 06 Aug 2021, 14:15 UTC

In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

CVE-2021-37548 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.

CVE-2021-37547 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.

CVE-2021-37546 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

CVE-2021-37545 jetbrains vulnerability CVSS: 5.0 06 Aug 2021, 14:15 UTC

In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.

CVE-2021-37544 jetbrains vulnerability CVSS: 7.5 06 Aug 2021, 14:15 UTC

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

CVE-2021-37542 jetbrains vulnerability CVSS: 4.3 06 Aug 2021, 14:15 UTC

In JetBrains TeamCity before 2020.2.3, XSS was possible.

CVE-2021-37541 jetbrains vulnerability CVSS: 4.3 06 Aug 2021, 14:15 UTC

In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

CVE-2021-37540 jetbrains vulnerability CVSS: 6.4 06 Aug 2021, 14:15 UTC

In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.

CVE-2021-36209 jetbrains vulnerability CVSS: 7.5 06 Aug 2021, 14:15 UTC

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

CVE-2021-31915 jetbrains vulnerability CVSS: 7.5 11 May 2021, 13:15 UTC

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

CVE-2021-31914 jetbrains vulnerability CVSS: 7.5 11 May 2021, 13:15 UTC

In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.

CVE-2021-31913 jetbrains vulnerability CVSS: 5.0 11 May 2021, 13:15 UTC

In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.

CVE-2021-31912 jetbrains vulnerability CVSS: 6.8 11 May 2021, 13:15 UTC

In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

CVE-2021-31911 jetbrains vulnerability CVSS: 4.3 11 May 2021, 13:15 UTC

In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.

CVE-2021-31910 jetbrains vulnerability CVSS: 5.0 11 May 2021, 13:15 UTC

In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.

CVE-2021-30482 jetbrains vulnerability CVSS: 5.0 11 May 2021, 13:15 UTC

In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

CVE-2021-3315 jetbrains vulnerability CVSS: 3.5 11 May 2021, 12:15 UTC

In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.

CVE-2021-31909 jetbrains vulnerability CVSS: 7.5 11 May 2021, 12:15 UTC

In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.

CVE-2021-31908 jetbrains vulnerability CVSS: 3.5 11 May 2021, 12:15 UTC

In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.

CVE-2021-31907 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.

CVE-2021-31906 jetbrains vulnerability CVSS: 4.0 11 May 2021, 12:15 UTC

In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.

CVE-2021-31905 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

CVE-2021-31904 jetbrains vulnerability CVSS: 4.3 11 May 2021, 12:15 UTC

In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.

CVE-2021-31903 jetbrains vulnerability CVSS: 4.3 11 May 2021, 12:15 UTC

In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.

CVE-2021-31902 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

CVE-2021-31901 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.

CVE-2021-30504 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.

CVE-2021-30006 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

CVE-2021-30005 jetbrains vulnerability CVSS: 4.6 11 May 2021, 12:15 UTC

In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

CVE-2021-29263 jetbrains vulnerability CVSS: 4.6 11 May 2021, 12:15 UTC

In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.

CVE-2021-27733 jetbrains vulnerability CVSS: 3.5 11 May 2021, 12:15 UTC

In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.

CVE-2021-26310 jetbrains vulnerability CVSS: 5.0 11 May 2021, 12:15 UTC

In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.

CVE-2021-26309 jetbrains vulnerability CVSS: 2.1 11 May 2021, 12:15 UTC

Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.

CVE-2021-25778 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.

CVE-2021-25777 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.

CVE-2021-25776 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.

CVE-2021-25775 jetbrains vulnerability CVSS: 5.5 03 Feb 2021, 16:15 UTC

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVE-2021-25774 jetbrains vulnerability CVSS: 4.0 03 Feb 2021, 16:15 UTC

In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.

CVE-2021-25773 jetbrains vulnerability CVSS: 4.3 03 Feb 2021, 16:15 UTC

JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.

CVE-2021-25772 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.

CVE-2021-25771 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.

CVE-2021-25770 jetbrains vulnerability CVSS: 7.5 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.

CVE-2021-25769 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.

CVE-2021-25768 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.

CVE-2021-25767 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.

CVE-2021-25766 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.

CVE-2021-25765 jetbrains vulnerability CVSS: 6.8 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.

CVE-2021-25763 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.

CVE-2021-25762 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.

CVE-2021-25761 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

CVE-2021-25760 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.

CVE-2021-25759 jetbrains vulnerability CVSS: 4.0 03 Feb 2021, 16:15 UTC

In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.

CVE-2021-25758 jetbrains vulnerability CVSS: 4.6 03 Feb 2021, 16:15 UTC

In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.

CVE-2021-25757 jetbrains vulnerability CVSS: 5.8 03 Feb 2021, 16:15 UTC

In JetBrains Hub before 2020.1.12629, an open redirect was possible.

CVE-2021-25756 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.

CVE-2020-35667 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.

CVE-2020-29582 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

CVE-2020-25208 jetbrains vulnerability CVSS: 5.0 03 Feb 2021, 16:15 UTC

In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.

CVE-2020-27627 jetbrains vulnerability CVSS: 5.8 16 Nov 2020, 16:15 UTC

JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.

CVE-2020-27623 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 16:15 UTC

JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.

CVE-2020-27622 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 16:15 UTC

In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.

CVE-2020-26129 jetbrains vulnerability CVSS: 6.4 16 Nov 2020, 16:15 UTC

In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.

CVE-2020-27629 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.

CVE-2020-27628 jetbrains vulnerability CVSS: 4.0 16 Nov 2020, 15:15 UTC

In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.

CVE-2020-27626 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.

CVE-2020-27625 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.

CVE-2020-27624 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.

CVE-2020-25210 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.

CVE-2020-25209 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

CVE-2020-25207 jetbrains vulnerability CVSS: 10.0 16 Nov 2020, 15:15 UTC

JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.

CVE-2020-25013 jetbrains vulnerability CVSS: 5.0 16 Nov 2020, 15:15 UTC

JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.

CVE-2020-24366 jetbrains vulnerability CVSS: 2.1 16 Nov 2020, 15:15 UTC

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

CVE-2020-15822 jetbrains vulnerability CVSS: 7.5 19 Oct 2020, 19:15 UTC

In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

CVE-2020-24618 jetbrains vulnerability CVSS: 4.0 27 Aug 2020, 20:15 UTC

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

CVE-2020-15831 jetbrains vulnerability CVSS: 4.3 08 Aug 2020, 21:15 UTC

JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.

CVE-2020-15830 jetbrains vulnerability CVSS: 4.3 08 Aug 2020, 21:15 UTC

JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.

CVE-2020-15829 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

CVE-2020-15828 jetbrains vulnerability CVSS: 4.0 08 Aug 2020, 21:15 UTC

In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.

CVE-2020-15827 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.

CVE-2020-15826 jetbrains vulnerability CVSS: 4.0 08 Aug 2020, 21:15 UTC

In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

CVE-2020-15825 jetbrains vulnerability CVSS: 6.5 08 Aug 2020, 21:15 UTC

In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.

CVE-2020-15824 jetbrains vulnerability CVSS: 6.5 08 Aug 2020, 21:15 UTC

In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.

CVE-2020-15823 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

CVE-2020-15821 jetbrains vulnerability CVSS: 4.0 08 Aug 2020, 21:15 UTC

In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

CVE-2020-15820 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.

CVE-2020-15819 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.

CVE-2020-15818 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.

CVE-2020-15817 jetbrains vulnerability CVSS: 6.5 08 Aug 2020, 21:15 UTC

In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.

CVE-2019-19704 jetbrains vulnerability CVSS: 5.0 08 Aug 2020, 21:15 UTC

In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.

CVE-2020-11938 jetbrains vulnerability CVSS: 4.0 22 Apr 2020, 14:15 UTC

In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.

CVE-2020-11796 jetbrains vulnerability CVSS: 7.5 22 Apr 2020, 14:15 UTC

In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.

CVE-2020-11795 jetbrains vulnerability CVSS: 5.0 22 Apr 2020, 14:15 UTC

In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.

CVE-2020-11693 jetbrains vulnerability CVSS: 5.0 22 Apr 2020, 14:15 UTC

JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.

CVE-2020-11692 jetbrains vulnerability CVSS: 4.0 22 Apr 2020, 14:15 UTC

In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.

CVE-2020-11691 jetbrains vulnerability CVSS: 5.0 22 Apr 2020, 14:15 UTC

In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.

CVE-2020-11690 jetbrains vulnerability CVSS: 7.5 22 Apr 2020, 14:15 UTC

In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.

CVE-2020-11689 jetbrains vulnerability CVSS: 4.0 22 Apr 2020, 14:15 UTC

In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.

CVE-2020-11688 jetbrains vulnerability CVSS: 5.0 22 Apr 2020, 14:15 UTC

In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.

CVE-2020-11687 jetbrains vulnerability CVSS: 5.0 22 Apr 2020, 14:15 UTC

In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.

CVE-2020-11686 jetbrains vulnerability CVSS: 4.0 22 Apr 2020, 14:15 UTC

In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.

CVE-2020-11685 jetbrains vulnerability CVSS: 5.0 22 Apr 2020, 14:15 UTC

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

CVE-2020-11416 jetbrains vulnerability CVSS: 3.5 22 Apr 2020, 14:15 UTC

JetBrains Space through 2020-04-22 allows stored XSS in Chats.

CVE-2020-11694 jetbrains vulnerability CVSS: 5.0 10 Apr 2020, 21:15 UTC

In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.

CVE-2020-7914 jetbrains vulnerability CVSS: 5.0 31 Jan 2020, 13:15 UTC

In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.

CVE-2020-7913 jetbrains vulnerability CVSS: 4.3 30 Jan 2020, 18:15 UTC

JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.

CVE-2020-7912 jetbrains vulnerability CVSS: 5.0 30 Jan 2020, 18:15 UTC

In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

CVE-2020-7911 jetbrains vulnerability CVSS: 4.3 30 Jan 2020, 18:15 UTC

In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.

CVE-2020-7910 jetbrains vulnerability CVSS: 3.5 30 Jan 2020, 18:15 UTC

JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.

CVE-2020-7909 jetbrains vulnerability CVSS: 5.0 30 Jan 2020, 18:15 UTC

In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

CVE-2020-7908 jetbrains vulnerability CVSS: 4.3 30 Jan 2020, 18:15 UTC

In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.

CVE-2020-7906 jetbrains vulnerability CVSS: 5.0 30 Jan 2020, 18:15 UTC

In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

CVE-2020-7905 jetbrains vulnerability CVSS: 5.0 30 Jan 2020, 18:15 UTC

Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

CVE-2020-7904 jetbrains vulnerability CVSS: 5.8 30 Jan 2020, 18:15 UTC

In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

CVE-2020-5207 jetbrains vulnerability CVSS: 5.0 27 Jan 2020, 20:15 UTC

In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.

CVE-2019-19389 jetbrains vulnerability CVSS: 3.5 26 Dec 2019, 21:15 UTC

JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.

CVE-2019-19703 jetbrains vulnerability CVSS: 5.8 10 Dec 2019, 20:15 UTC

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.

CVE-2019-18369 jetbrains vulnerability CVSS: 5.0 31 Oct 2019, 16:15 UTC

In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

CVE-2019-18368 jetbrains vulnerability CVSS: 7.5 31 Oct 2019, 16:15 UTC

In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

CVE-2019-18367 jetbrains vulnerability CVSS: 5.0 31 Oct 2019, 16:15 UTC

In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

CVE-2019-18366 jetbrains vulnerability CVSS: 5.0 31 Oct 2019, 16:15 UTC

In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.

CVE-2019-18365 jetbrains vulnerability CVSS: 4.3 31 Oct 2019, 16:15 UTC

In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

CVE-2019-18364 jetbrains vulnerability CVSS: 7.5 31 Oct 2019, 15:15 UTC

In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

CVE-2019-18363 jetbrains vulnerability CVSS: 5.0 31 Oct 2019, 15:15 UTC

In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.

CVE-2019-18362 jetbrains vulnerability CVSS: 5.0 31 Oct 2019, 15:15 UTC

JetBrains MPS before 2019.2.2 exposed listening ports to the network.

CVE-2019-18361 jetbrains vulnerability CVSS: 4.6 31 Oct 2019, 15:15 UTC

JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.

CVE-2019-18360 jetbrains vulnerability CVSS: 5.0 31 Oct 2019, 15:15 UTC

In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.

CVE-2019-16407 jetbrains vulnerability CVSS: 4.4 02 Oct 2019, 19:15 UTC

JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.

CVE-2019-16171 jetbrains vulnerability CVSS: 4.3 02 Oct 2019, 19:15 UTC

In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.

CVE-2019-15040 jetbrains vulnerability CVSS: 6.8 02 Oct 2019, 19:15 UTC

JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.

CVE-2019-15037 jetbrains vulnerability CVSS: 4.3 02 Oct 2019, 19:15 UTC

An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.

CVE-2019-15036 jetbrains vulnerability CVSS: 9.0 02 Oct 2019, 19:15 UTC

An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.

CVE-2019-14959 jetbrains vulnerability CVSS: 4.3 02 Oct 2019, 19:15 UTC

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

CVE-2019-14958 jetbrains vulnerability CVSS: 5.0 02 Oct 2019, 19:15 UTC

JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.

CVE-2019-14956 jetbrains vulnerability CVSS: 4.0 02 Oct 2019, 19:15 UTC

JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.

CVE-2019-12737 jetbrains vulnerability CVSS: 5.0 02 Oct 2019, 19:15 UTC

UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.

CVE-2019-12736 jetbrains vulnerability CVSS: 7.5 02 Oct 2019, 19:15 UTC

JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

CVE-2019-12157 jetbrains vulnerability CVSS: 10.0 02 Oct 2019, 19:15 UTC

In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.

CVE-2019-12156 jetbrains vulnerability CVSS: 5.0 02 Oct 2019, 19:15 UTC

Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.

CVE-2019-15041 jetbrains vulnerability CVSS: 5.8 01 Oct 2019, 20:15 UTC

JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.

CVE-2019-15035 jetbrains vulnerability CVSS: 4.0 01 Oct 2019, 20:15 UTC

An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.

CVE-2019-15042 jetbrains vulnerability CVSS: 5.0 01 Oct 2019, 17:15 UTC

An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.

CVE-2019-14961 jetbrains vulnerability CVSS: 4.3 01 Oct 2019, 17:15 UTC

JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.

CVE-2019-15038 jetbrains vulnerability CVSS: 5.0 01 Oct 2019, 16:15 UTC

An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.

CVE-2019-14960 jetbrains vulnerability CVSS: 4.6 01 Oct 2019, 16:15 UTC

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

CVE-2019-14957 jetbrains vulnerability CVSS: 5.0 01 Oct 2019, 16:15 UTC

The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.

CVE-2019-14955 jetbrains vulnerability CVSS: 5.0 01 Oct 2019, 16:15 UTC

In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.

CVE-2019-14953 jetbrains vulnerability CVSS: 4.3 01 Oct 2019, 16:15 UTC

JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.

CVE-2019-15039 jetbrains vulnerability CVSS: 6.8 01 Oct 2019, 14:15 UTC

An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.

CVE-2019-14954 jetbrains vulnerability CVSS: 4.3 01 Oct 2019, 14:15 UTC

JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.

CVE-2019-14952 jetbrains vulnerability CVSS: 4.3 01 Oct 2019, 14:15 UTC

JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.

CVE-2019-15848 jetbrains vulnerability CVSS: 4.3 05 Sep 2019, 20:15 UTC

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

CVE-2019-12852 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 20:15 UTC

An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.

CVE-2019-12846 jetbrains vulnerability CVSS: 4.0 03 Jul 2019, 20:15 UTC

A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.

CVE-2019-12845 jetbrains vulnerability CVSS: 5.0 03 Jul 2019, 20:15 UTC

The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.

CVE-2019-12844 jetbrains vulnerability CVSS: 4.3 03 Jul 2019, 20:15 UTC

A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

CVE-2019-12843 jetbrains vulnerability CVSS: 4.3 03 Jul 2019, 20:15 UTC

A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.

CVE-2019-12842 jetbrains vulnerability CVSS: 4.3 03 Jul 2019, 20:15 UTC

A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.

CVE-2019-12841 jetbrains vulnerability CVSS: 5.0 03 Jul 2019, 20:15 UTC

Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.

CVE-2019-10103 jetbrains vulnerability CVSS: 6.8 03 Jul 2019, 20:15 UTC

JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

CVE-2019-10102 jetbrains vulnerability CVSS: 6.8 03 Jul 2019, 20:15 UTC

JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.

CVE-2019-10101 jetbrains vulnerability CVSS: 6.8 03 Jul 2019, 20:15 UTC

JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.

CVE-2019-9873 jetbrains vulnerability CVSS: 5.0 03 Jul 2019, 19:15 UTC

In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.

CVE-2019-9872 jetbrains vulnerability CVSS: 4.3 03 Jul 2019, 19:15 UTC

In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.

CVE-2019-9823 jetbrains vulnerability CVSS: 5.0 03 Jul 2019, 19:15 UTC

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.

CVE-2019-9186 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 19:15 UTC

In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

CVE-2019-12867 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 19:15 UTC

Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

CVE-2019-12866 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 19:15 UTC

An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

CVE-2019-12851 jetbrains vulnerability CVSS: 6.8 03 Jul 2019, 19:15 UTC

A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

CVE-2019-12850 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 19:15 UTC

A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.

CVE-2019-12847 jetbrains vulnerability CVSS: 4.0 03 Jul 2019, 19:15 UTC

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

CVE-2019-10104 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 19:15 UTC

In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

CVE-2019-10100 jetbrains vulnerability CVSS: 7.5 03 Jul 2019, 19:15 UTC

In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.

CVE-2018-14878 jetbrains vulnerability CVSS: 6.8 13 Aug 2018, 17:29 UTC

JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.

CVE-2017-8316 jetbrains vulnerability CVSS: 7.8 03 Aug 2018, 15:29 UTC

IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.

CVE-2014-10036 jetbrains vulnerability CVSS: 4.3 13 Jan 2015, 15:59 UTC

Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.

CVE-2014-10002 jetbrains vulnerability CVSS: 5.0 13 Jan 2015, 11:59 UTC

Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors.