Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-29880 | Med | 0.27 | 4.2 | 0.00 | Mar 21, 2024 | In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | ||
| CVE-2022-48477 | Med | 0.27 | 4.1 | 0.00 | Apr 24, 2023 | In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing | ||
| CVE-2022-46830 | Med | 0.27 | 4.1 | 0.00 | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. | ||
| CVE-2022-38180 | Med | 0.27 | 5.3 | 0.01 | Aug 12, 2022 | In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases | ||
| CVE-2022-37396 | Med | 0.27 | 4.1 | 0.00 | Aug 3, 2022 | In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution | ||
| CVE-2022-36321 | Med | 0.27 | 4.1 | 0.02 | Jul 20, 2022 | In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases | ||
| CVE-2022-46825 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. | ||
| CVE-2025-67742 | Low | 0.25 | 3.8 | 0.01 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11 path traversal was possible via file upload | ||
| CVE-2025-46618 | Low | 0.25 | 3.5 | 0.59 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab | ||
| CVE-2022-46827 | Low | 0.25 | 3.9 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible. | ||
| CVE-2022-37009 | Low | 0.25 | 3.9 | 0.00 | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible | ||
| CVE-2022-29818 | Low | 0.25 | 3.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed | ||
| CVE-2022-29817 | Low | 0.25 | 3.9 | 0.00 | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible | ||
| CVE-2021-25775 | Low | 0.25 | 3.8 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | ||
| CVE-2025-54529 | Low | 0.24 | 3.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | ||
| CVE-2024-54155 | Low | 0.24 | 3.7 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | ||
| CVE-2024-43808 | Low | 0.24 | 3.7 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin | ||
| CVE-2022-38179 | Med | 0.24 | 4.7 | 0.00 | Aug 12, 2022 | JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack | ||
| CVE-2022-29929 | Low | 0.24 | 3.7 | 0.00 | May 12, 2022 | In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible | ||
| CVE-2025-68163 | Low | 0.23 | 3.5 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page | ||
| CVE-2024-54158 | Low | 0.23 | 3.5 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | ||
| CVE-2024-47951 | Low | 0.23 | 3.5 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | ||
| CVE-2024-47950 | Low | 0.23 | 3.5 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | ||
| CVE-2024-43809 | Low | 0.23 | 3.5 | 0.00 | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page | ||
| CVE-2024-41829 | Low | 0.23 | 3.5 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | ||
| CVE-2024-41826 | Low | 0.23 | 3.5 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | ||
| CVE-2024-38507 | Low | 0.23 | 3.5 | 0.00 | Jun 18, 2024 | In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible | ||
| CVE-2024-35300 | Low | 0.23 | 3.5 | 0.00 | May 16, 2024 | In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible | ||
| CVE-2023-43566 | Low | 0.23 | 3.5 | 0.01 | Sep 19, 2023 | In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration | ||
| CVE-2023-41250 | Low | 0.23 | 3.5 | 0.00 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | ||
| CVE-2022-45471 | Low | 0.23 | 3.5 | 0.01 | Nov 18, 2022 | In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address | ||
| CVE-2022-37010 | Low | 0.23 | 3.6 | 0.00 | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed | ||
| CVE-2022-34894 | Low | 0.23 | 3.5 | 0.01 | Jul 1, 2022 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services | ||
| CVE-2026-49381 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | ||
| CVE-2026-49370 | Low | 0.22 | 3.4 | 0.00 | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests | ||
| CVE-2026-49383 | Low | 0.21 | 3.3 | 0.00 | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible | ||
| CVE-2025-32054 | Low | 0.21 | 3.3 | 0.00 | Apr 3, 2025 | In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file | ||
| CVE-2024-46970 | Low | 0.21 | 3.3 | 0.00 | Sep 16, 2024 | In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible | ||
| CVE-2024-5899 | Low | 0.21 | 3.3 | 0.00 | Jun 18, 2024 | When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls… | ||
| CVE-2024-24939 | Low | 0.21 | 3.3 | 0.00 | Feb 6, 2024 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible | ||
| CVE-2023-38069 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2023 | In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases | ||
| CVE-2023-34339 | Low | 0.21 | 3.3 | 0.00 | Jun 1, 2023 | In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message | ||
| CVE-2022-48435 | Low | 0.21 | 3.3 | 0.00 | Apr 4, 2023 | In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file | ||
| CVE-2022-38133 | Low | 0.21 | 3.2 | 0.00 | Aug 10, 2022 | In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases | ||
| CVE-2021-26309 | Low | 0.21 | 3.3 | 0.00 | May 11, 2021 | Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions. | ||
| CVE-2020-24366 | Low | 0.21 | 3.3 | 0.00 | Nov 16, 2020 | Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups. | ||
| CVE-2026-49380 | Low | 0.20 | 3.1 | 0.00 | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | ||
| CVE-2025-67739 | Low | 0.20 | 3.1 | 0.00 | Dec 11, 2025 | In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure | ||
| CVE-2024-54153 | Low | 0.20 | 3.1 | 0.00 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | ||
| CVE-2022-29820 | Low | 0.20 | 3.0 | 0.00 | Apr 28, 2022 | In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible |
- risk 0.27cvss 4.2epss 0.00
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process
- risk 0.27cvss 4.1epss 0.00
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
- risk 0.27cvss 4.1epss 0.00
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
- risk 0.27cvss 5.3epss 0.01
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
- risk 0.27cvss 4.1epss 0.00
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
- risk 0.27cvss 4.1epss 0.02
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
- risk 0.26cvss 4.0epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
- risk 0.25cvss 3.8epss 0.01
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
- risk 0.25cvss 3.5epss 0.59
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
- risk 0.25cvss 3.8epss 0.01
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
- risk 0.24cvss 3.7epss 0.00
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
- risk 0.24cvss 4.7epss 0.00
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
- risk 0.24cvss 3.7epss 0.00
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
- risk 0.23cvss 3.5epss 0.00
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
- risk 0.23cvss 3.5epss 0.00
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
- risk 0.23cvss 3.5epss 0.01
In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration
- risk 0.23cvss 3.5epss 0.00
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration
- risk 0.23cvss 3.5epss 0.01
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
- risk 0.23cvss 3.6epss 0.00
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed
- risk 0.23cvss 3.5epss 0.01
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
- risk 0.22cvss 3.4epss 0.00
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
- risk 0.22cvss 3.4epss 0.00
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
- risk 0.21cvss 3.3epss 0.00
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls…
- risk 0.21cvss 3.3epss 0.00
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
- risk 0.21cvss 3.3epss 0.00
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases
- risk 0.21cvss 3.3epss 0.00
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
- risk 0.21cvss 3.3epss 0.00
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
- risk 0.21cvss 3.2epss 0.00
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
- risk 0.21cvss 3.3epss 0.00
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
- risk 0.21cvss 3.3epss 0.00
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
- risk 0.20cvss 3.1epss 0.00
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
- risk 0.20cvss 3.1epss 0.00
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
- risk 0.20cvss 3.1epss 0.00
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
- risk 0.20cvss 3.0epss 0.00
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
Page 11 of 13