Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28195 | Med | 0.28 | 4.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | ||
| CVE-2026-28194 | Med | 0.28 | 4.3 | 0.00 | Feb 25, 2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow | ||
| CVE-2025-64684 | Med | 0.28 | 4.3 | 0.00 | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form | ||
| CVE-2025-57734 | Med | 0.28 | 4.3 | 0.01 | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files | ||
| CVE-2025-54533 | Med | 0.28 | 4.3 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration | ||
| CVE-2025-54532 | Med | 0.28 | 4.3 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | ||
| CVE-2025-52878 | Med | 0.28 | 4.3 | 0.00 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions | ||
| CVE-2025-47854 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page | ||
| CVE-2025-47850 | Med | 0.28 | 4.3 | 0.00 | May 20, 2025 | In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning | ||
| CVE-2025-46432 | Med | 0.28 | 4.3 | 0.01 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs | ||
| CVE-2025-31139 | Med | 0.28 | 4.3 | 0.01 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log | ||
| CVE-2025-24460 | Med | 0.28 | 4.3 | 0.00 | Jan 21, 2025 | In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool | ||
| CVE-2024-56350 | Med | 0.28 | 4.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects | ||
| CVE-2024-56348 | Med | 0.28 | 4.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents | ||
| CVE-2024-54157 | Med | 0.28 | 4.3 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | ||
| CVE-2024-50573 | Med | 0.28 | 4.3 | 0.00 | Oct 28, 2024 | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services | ||
| CVE-2024-47161 | Med | 0.28 | 4.3 | 0.00 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API | ||
| CVE-2024-47160 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | ||
| CVE-2024-47159 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project | ||
| CVE-2024-38504 | Med | 0.28 | 4.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | ||
| CVE-2024-28173 | Med | 0.28 | 4.3 | 0.01 | Mar 6, 2024 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed | ||
| CVE-2024-24936 | Med | 0.28 | 4.3 | 0.00 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed | ||
| CVE-2023-50871 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2023 | In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | ||
| CVE-2023-50870 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2023 | In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible | ||
| CVE-2023-39174 | Med | 0.28 | 4.3 | 0.02 | Jul 25, 2023 | In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers | ||
| CVE-2023-38067 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log | ||
| CVE-2023-38064 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log | ||
| CVE-2023-38062 | Med | 0.28 | 4.3 | 0.01 | Jul 12, 2023 | In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations | ||
| CVE-2023-34223 | Med | 0.28 | 4.3 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | ||
| CVE-2023-34219 | Med | 0.28 | 4.3 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API | ||
| CVE-2022-24343 | Med | 0.28 | 4.3 | 0.01 | Feb 25, 2022 | In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. | ||
| CVE-2021-37554 | Med | 0.28 | 4.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. | ||
| CVE-2021-25774 | Med | 0.28 | 4.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. | ||
| CVE-2021-25771 | Med | 0.28 | 4.3 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. | ||
| CVE-2020-27628 | Med | 0.28 | 4.3 | 0.01 | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records. | ||
| CVE-2020-15826 | Med | 0.28 | 4.3 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have. | ||
| CVE-2020-7908 | Med | 0.28 | 4.3 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages. | ||
| CVE-2020-5207 | Med | 0.28 | 5.4 | 0.01 | Jan 27, 2020 | In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator. | ||
| CVE-2019-18365 | Med | 0.28 | 4.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages. | ||
| CVE-2019-14956 | Med | 0.28 | 4.3 | 0.01 | Oct 2, 2019 | JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names. | ||
| CVE-2019-12846 | Med | 0.28 | 4.3 | 0.01 | Jul 3, 2019 | A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2025-64457 | Med | 0.27 | 4.2 | 0.00 | Nov 10, 2025 | In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition | ||
| CVE-2025-59455 | Med | 0.27 | 4.2 | 0.00 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition | ||
| CVE-2025-42921 | Med | 0.27 | 4.2 | 0.00 | Apr 17, 2025 | In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin | ||
| CVE-2025-29932 | Med | 0.27 | 4.1 | 0.00 | Mar 25, 2025 | In JetBrains GoLand before 2025.1 an XXE during debugging was possible | ||
| CVE-2024-54156 | Med | 0.27 | 4.2 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | ||
| CVE-2024-49580 | Med | 0.27 | 5.3 | 0.00 | Oct 17, 2024 | In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure | ||
| CVE-2024-47162 | Med | 0.27 | 4.1 | 0.00 | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | ||
| CVE-2024-39878 | Med | 0.27 | 4.1 | 0.00 | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection | ||
| CVE-2024-31140 | Med | 0.27 | 4.1 | 0.00 | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools |
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
- risk 0.28cvss 4.3epss 0.00
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
- risk 0.28cvss 4.3epss 0.00
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
- risk 0.28cvss 4.3epss 0.02
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
- risk 0.28cvss 4.3epss 0.00
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
- risk 0.28cvss 4.3epss 0.01
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
- risk 0.28cvss 4.3epss 0.02
In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
- risk 0.28cvss 5.4epss 0.01
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
- risk 0.28cvss 4.3epss 0.01
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
- risk 0.28cvss 4.3epss 0.01
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
- risk 0.28cvss 4.3epss 0.01
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
- risk 0.27cvss 4.2epss 0.00
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
- risk 0.27cvss 4.2epss 0.00
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
- risk 0.27cvss 4.2epss 0.00
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
- risk 0.27cvss 4.1epss 0.00
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
- risk 0.27cvss 4.2epss 0.00
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
- risk 0.27cvss 5.3epss 0.00
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
- risk 0.27cvss 4.1epss 0.00
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
- risk 0.27cvss 4.1epss 0.00
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
- risk 0.27cvss 4.1epss 0.00
In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools
Page 10 of 13