Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24344 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. | ||
| CVE-2022-24339 | Med | 0.35 | 5.4 | 0.00 | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. | ||
| CVE-2022-24336 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server. | ||
| CVE-2022-24334 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. | ||
| CVE-2022-24332 | Med | 0.35 | 5.3 | 0.01 | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie. | ||
| CVE-2022-24329 | Med | 0.35 | 5.3 | 0.02 | Feb 25, 2022 | In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. | ||
| CVE-2021-43201 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. | ||
| CVE-2021-43199 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient. | ||
| CVE-2021-43198 | Med | 0.35 | 5.4 | 0.00 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, stored XSS is possible. | ||
| CVE-2021-43195 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. | ||
| CVE-2021-43194 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains TeamCity before 2021.1.2, user enumeration was possible. | ||
| CVE-2021-43192 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. | ||
| CVE-2021-43191 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. | ||
| CVE-2021-43190 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. | ||
| CVE-2021-43187 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. | ||
| CVE-2021-43186 | Med | 0.35 | 5.4 | 0.01 | Nov 9, 2021 | JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. | ||
| CVE-2021-43184 | Med | 0.35 | 5.4 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. | ||
| CVE-2021-37552 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. | ||
| CVE-2021-37551 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | ||
| CVE-2021-37547 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made. | ||
| CVE-2021-3315 | Med | 0.35 | 5.4 | 0.00 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. | ||
| CVE-2021-31908 | Med | 0.35 | 5.4 | 0.00 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages. | ||
| CVE-2021-31907 | Med | 0.35 | 5.3 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly. | ||
| CVE-2021-31900 | Med | 0.35 | 5.3 | 0.01 | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host. | ||
| CVE-2021-27733 | Med | 0.35 | 5.4 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. | ||
| CVE-2021-25764 | Med | 0.35 | 5.3 | 0.01 | Mar 18, 2021 | In JetBrains PhpStorm before 2020.3, source code could be added to debug logs. | ||
| CVE-2021-25778 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly. | ||
| CVE-2021-25777 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. | ||
| CVE-2021-25772 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. | ||
| CVE-2021-25768 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. | ||
| CVE-2021-25767 | Med | 0.35 | 5.3 | 0.03 | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. | ||
| CVE-2021-25766 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. | ||
| CVE-2021-25762 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible. | ||
| CVE-2021-25760 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible. | ||
| CVE-2021-25756 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. | ||
| CVE-2020-29582 | Med | 0.35 | 5.3 | 0.03 | Feb 3, 2021 | In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions. | ||
| CVE-2020-25208 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions. | ||
| CVE-2020-27622 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version. | ||
| CVE-2020-27629 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts. | ||
| CVE-2020-27626 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. | ||
| CVE-2020-27625 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues. | ||
| CVE-2020-27624 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. | ||
| CVE-2020-25210 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants. | ||
| CVE-2020-15829 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs. | ||
| CVE-2020-15820 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence. | ||
| CVE-2020-15819 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. | ||
| CVE-2020-15818 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence. | ||
| CVE-2020-11416 | Med | 0.35 | 5.4 | 0.01 | Apr 22, 2020 | JetBrains Space through 2020-04-22 allows stored XSS in Chats. | ||
| CVE-2020-7912 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. | ||
| CVE-2020-7910 | Med | 0.35 | 5.4 | 0.01 | Jan 30, 2020 | JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. |
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
- risk 0.35cvss 5.4epss 0.00
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
- risk 0.35cvss 5.3epss 0.02
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
- risk 0.35cvss 5.3epss 0.01
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
- risk 0.35cvss 5.3epss 0.03
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
- risk 0.35cvss 5.3epss 0.03
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
- risk 0.35cvss 5.4epss 0.01
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
- risk 0.35cvss 5.4epss 0.01
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
Page 7 of 13