Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25264 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. | ||
| CVE-2022-24341 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user. | ||
| CVE-2022-24327 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. | ||
| CVE-2021-43182 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. | ||
| CVE-2021-43180 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. | ||
| CVE-2021-43203 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. | ||
| CVE-2021-43196 | Hig | 0.49 | 7.5 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. | ||
| CVE-2021-37553 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. | ||
| CVE-2021-37550 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. | ||
| CVE-2021-37548 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS. | ||
| CVE-2021-37545 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. | ||
| CVE-2021-31913 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange. | ||
| CVE-2021-31910 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible. | ||
| CVE-2021-31898 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. | ||
| CVE-2021-30482 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly | ||
| CVE-2021-31905 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible. | ||
| CVE-2021-31902 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. | ||
| CVE-2021-31901 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group. | ||
| CVE-2021-30504 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation. | ||
| CVE-2021-30006 | Hig | 0.49 | 7.5 | 0.01 | May 11, 2021 | In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. | ||
| CVE-2021-26310 | Hig | 0.49 | 7.5 | 0.02 | May 11, 2021 | In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible. | ||
| CVE-2021-25776 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. | ||
| CVE-2021-25769 | Hig | 0.49 | 7.5 | 0.02 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. | ||
| CVE-2020-35667 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2021 | JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials. | ||
| CVE-2020-27623 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2020 | JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances. | ||
| CVE-2020-25209 | Hig | 0.49 | 7.5 | 0.02 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API. | ||
| CVE-2020-25013 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2020 | JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. | ||
| CVE-2020-15827 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2020 | In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file. | ||
| CVE-2020-15823 | Hig | 0.49 | 7.5 | 0.02 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component. | ||
| CVE-2019-19704 | Hig | 0.49 | 7.5 | 0.01 | Aug 8, 2020 | In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm. | ||
| CVE-2020-11795 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. | ||
| CVE-2020-11693 | Hig | 0.49 | 7.5 | 0.02 | Apr 22, 2020 | JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. | ||
| CVE-2020-11691 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible. | ||
| CVE-2020-11688 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. | ||
| CVE-2020-11687 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. | ||
| CVE-2020-11685 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2020 | In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. | ||
| CVE-2020-11694 | Hig | 0.49 | 7.5 | 0.02 | Apr 10, 2020 | In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. | ||
| CVE-2020-7907 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2020 | In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. | ||
| CVE-2020-7914 | Hig | 0.49 | 7.5 | 0.02 | Jan 31, 2020 | In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3. | ||
| CVE-2020-7909 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. | ||
| CVE-2020-7906 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. | ||
| CVE-2020-7905 | Hig | 0.49 | 7.5 | 0.01 | Jan 30, 2020 | Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. | ||
| CVE-2019-18412 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2020 | JetBrains IDETalk plugin before version 193.4099.10 allows XXE | ||
| CVE-2019-14958 | Hig | 0.49 | 7.5 | 0.02 | Oct 2, 2019 | JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation. | ||
| CVE-2019-15042 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1. | ||
| CVE-2019-15038 | Hig | 0.49 | 7.5 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1. | ||
| CVE-2019-12841 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2019 | Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2. | ||
| CVE-2017-8316 | Hig | 0.49 | 7.5 | 0.02 | Aug 3, 2018 | IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml. | ||
| CVE-2026-41882 | Hig | 0.48 | 7.4 | 0.00 | Apr 30, 2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | ||
| CVE-2024-41827 | Hig | 0.48 | 7.4 | 0.00 | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration |
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.
- risk 0.49cvss 7.5epss 0.01
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
- risk 0.49cvss 7.5epss 0.02
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
- risk 0.49cvss 7.5epss 0.01
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
- risk 0.49cvss 7.5epss 0.02
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
- risk 0.49cvss 7.5epss 0.01
JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.
- risk 0.49cvss 7.5epss 0.01
JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.
- risk 0.49cvss 7.5epss 0.02
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
- risk 0.49cvss 7.5epss 0.01
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
- risk 0.49cvss 7.5epss 0.01
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
- risk 0.49cvss 7.5epss 0.02
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
- risk 0.49cvss 7.5epss 0.01
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
- risk 0.49cvss 7.5epss 0.02
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
- risk 0.49cvss 7.5epss 0.01
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
- risk 0.49cvss 7.5epss 0.02
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.
- risk 0.49cvss 7.5epss 0.01
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
- risk 0.49cvss 7.5epss 0.01
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.
- risk 0.49cvss 7.5epss 0.01
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
- risk 0.49cvss 7.5epss 0.02
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
- risk 0.49cvss 7.5epss 0.01
Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.
- risk 0.49cvss 7.5epss 0.02
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
- risk 0.48cvss 7.4epss 0.00
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
- risk 0.48cvss 7.4epss 0.00
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
Page 3 of 13