VYPR

Vendor CVEs

Jetbrains

All CVEs

650 total · sorted by risk
  • CVE-2025-24460MedJan 21, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool

  • CVE-2024-56350MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects

  • CVE-2024-56348MedDec 20, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents

  • CVE-2024-54157MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

  • CVE-2024-50573MedOct 28, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

  • CVE-2024-47161MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

  • CVE-2024-47160MedSep 19, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

  • CVE-2024-47159MedSep 19, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

  • CVE-2024-38504MedJun 18, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

  • CVE-2024-28173MedMar 6, 2024
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

  • CVE-2024-24936MedFeb 6, 2024
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

  • CVE-2023-50871MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

  • CVE-2023-50870MedDec 15, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible

  • CVE-2023-39174MedJul 25, 2023
    risk 0.28cvss 4.3epss 0.02

    In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

  • CVE-2023-38067MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

  • CVE-2023-38064MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

  • CVE-2023-38062MedJul 12, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

  • CVE-2023-34223MedMay 31, 2023
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

  • CVE-2023-34219MedMay 31, 2023
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

  • CVE-2022-24343MedFeb 25, 2022
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

  • CVE-2021-37554MedAug 6, 2021
    risk 0.28cvss 4.3epss 0.01

    In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

  • CVE-2021-25774MedFeb 3, 2021
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.

  • CVE-2021-25771MedFeb 3, 2021
    risk 0.28cvss 4.3epss 0.02

    In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.

  • CVE-2020-27628MedNov 16, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.

  • CVE-2020-15826MedAug 8, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.

  • CVE-2020-7908MedJan 30, 2020
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.

  • CVE-2020-5207MedJan 27, 2020
    risk 0.28cvss 5.4epss 0.01

    In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.

  • CVE-2019-18365MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

  • CVE-2019-14956MedOct 2, 2019
    risk 0.28cvss 4.3epss 0.01

    JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.

  • CVE-2019-12846MedJul 3, 2019
    risk 0.28cvss 4.3epss 0.01

    A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.

  • CVE-2025-64457MedNov 10, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

  • CVE-2025-59455MedSep 17, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

  • CVE-2025-42921MedApr 17, 2025
    risk 0.27cvss 4.2epss 0.00

    In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin

  • CVE-2025-29932MedMar 25, 2025
    risk 0.27cvss 4.1epss 0.00

    In JetBrains GoLand before 2025.1 an XXE during debugging was possible

  • CVE-2024-54156MedDec 4, 2024
    risk 0.27cvss 4.2epss 0.00

    In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

  • CVE-2024-49580MedOct 17, 2024
    risk 0.27cvss 5.3epss 0.00

    In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

  • CVE-2024-47162MedSep 19, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

  • CVE-2024-39878MedJul 1, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

  • CVE-2024-31140MedMar 28, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

  • CVE-2024-29880MedMar 21, 2024
    risk 0.27cvss 4.2epss 0.00

    In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

  • CVE-2022-48477MedApr 24, 2023
    risk 0.27cvss 4.1epss 0.00

    In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing

  • CVE-2022-46830MedDec 8, 2022
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.

  • CVE-2022-38180MedAug 12, 2022
    risk 0.27cvss 5.3epss 0.01

    In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

  • CVE-2022-37396MedAug 3, 2022
    risk 0.27cvss 4.1epss 0.00

    In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution

  • CVE-2022-36321MedJul 20, 2022
    risk 0.27cvss 4.1epss 0.02

    In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases

  • CVE-2022-46825MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.

  • CVE-2025-67742LowDec 11, 2025
    risk 0.25cvss 3.8epss 0.01

    In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

  • CVE-2025-46618LowApr 25, 2025
    risk 0.25cvss 3.5epss 0.63

    In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

  • CVE-2022-46827LowDec 8, 2022
    risk 0.25cvss 3.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.

  • CVE-2022-37009LowJul 28, 2022
    risk 0.25cvss 3.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible