Vendor CVEs
Jetbrains
All CVEs
650 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37551 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | ||
| CVE-2021-37547 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made. | ||
| CVE-2021-3315 | Med | 0.35 | 5.4 | 0.00 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. | ||
| CVE-2021-31908 | Med | 0.35 | 5.4 | 0.00 | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages. | ||
| CVE-2021-31907 | Med | 0.35 | 5.3 | 0.01 | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly. | ||
| CVE-2021-31900 | Med | 0.35 | 5.3 | 0.01 | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host. | ||
| CVE-2021-27733 | Med | 0.35 | 5.4 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. | ||
| CVE-2021-25764 | Med | 0.35 | 5.3 | 0.01 | Mar 18, 2021 | In JetBrains PhpStorm before 2020.3, source code could be added to debug logs. | ||
| CVE-2021-25778 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly. | ||
| CVE-2021-25777 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. | ||
| CVE-2021-25772 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. | ||
| CVE-2021-25768 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. | ||
| CVE-2021-25767 | Med | 0.35 | 5.3 | 0.03 | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. | ||
| CVE-2021-25766 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. | ||
| CVE-2021-25762 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible. | ||
| CVE-2021-25760 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible. | ||
| CVE-2021-25756 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. | ||
| CVE-2020-29582 | Med | 0.35 | 5.3 | 0.03 | Feb 3, 2021 | In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions. | ||
| CVE-2020-25208 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions. | ||
| CVE-2020-27622 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version. | ||
| CVE-2020-27629 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts. | ||
| CVE-2020-27626 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. | ||
| CVE-2020-27625 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues. | ||
| CVE-2020-27624 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. | ||
| CVE-2020-25210 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants. | ||
| CVE-2020-15829 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs. | ||
| CVE-2020-15820 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence. | ||
| CVE-2020-15819 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. | ||
| CVE-2020-15818 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence. | ||
| CVE-2020-11416 | Med | 0.35 | 5.4 | 0.01 | Apr 22, 2020 | JetBrains Space through 2020-04-22 allows stored XSS in Chats. | ||
| CVE-2020-7912 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. | ||
| CVE-2020-7910 | Med | 0.35 | 5.4 | 0.01 | Jan 30, 2020 | JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. | ||
| CVE-2019-18369 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. | ||
| CVE-2019-18367 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions. | ||
| CVE-2019-18366 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission. | ||
| CVE-2019-18363 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances. | ||
| CVE-2019-18362 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | JetBrains MPS before 2019.2.2 exposed listening ports to the network. | ||
| CVE-2019-18360 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery. | ||
| CVE-2019-12737 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. | ||
| CVE-2019-12156 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293. | ||
| CVE-2019-14957 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2019 | The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository. | ||
| CVE-2019-14955 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2019 | In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented. | ||
| CVE-2019-12845 | Med | 0.35 | 5.3 | 0.01 | Jul 3, 2019 | The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3. | ||
| CVE-2025-64683 | Med | 0.34 | 5.3 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API | ||
| CVE-2025-57730 | Med | 0.34 | 5.2 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature | ||
| CVE-2025-29904 | Med | 0.34 | 5.3 | 0.00 | Mar 12, 2025 | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible | ||
| CVE-2025-29903 | Med | 0.34 | 5.2 | 0.00 | Mar 12, 2025 | In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible | ||
| CVE-2024-56349 | Med | 0.34 | 5.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | ||
| CVE-2024-50574 | Med | 0.34 | 5.3 | 0.01 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | ||
| CVE-2024-47949 | Med | 0.34 | 4.9 | 0.23 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location |
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
- risk 0.35cvss 5.4epss 0.00
In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
- risk 0.35cvss 5.3epss 0.01
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
- risk 0.35cvss 5.3epss 0.03
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
- risk 0.35cvss 5.3epss 0.03
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
- risk 0.35cvss 5.4epss 0.01
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
- risk 0.35cvss 5.4epss 0.01
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
- risk 0.35cvss 5.3epss 0.01
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
- risk 0.35cvss 5.3epss 0.01
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
- risk 0.35cvss 5.3epss 0.01
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
- risk 0.35cvss 5.3epss 0.01
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
- risk 0.35cvss 5.3epss 0.01
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
- risk 0.34cvss 5.3epss 0.00
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
- risk 0.34cvss 5.3epss 0.00
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
- risk 0.34cvss 5.2epss 0.00
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
- risk 0.34cvss 5.3epss 0.01
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
- risk 0.34cvss 4.9epss 0.23
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
Page 8 of 13