Vendor CVEs
Jetbrains
All CVEs
603 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18369 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. | ||
| CVE-2019-18367 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions. | ||
| CVE-2019-18366 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission. | ||
| CVE-2019-18363 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances. | ||
| CVE-2019-18362 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | JetBrains MPS before 2019.2.2 exposed listening ports to the network. | ||
| CVE-2019-18360 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery. | ||
| CVE-2019-12737 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. | ||
| CVE-2019-12156 | Med | 0.35 | 5.3 | 0.01 | Oct 2, 2019 | Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293. | ||
| CVE-2019-14957 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2019 | The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository. | ||
| CVE-2019-14955 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2019 | In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented. | ||
| CVE-2019-12845 | Med | 0.35 | 5.3 | 0.01 | Jul 3, 2019 | The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3. | ||
| CVE-2025-64683 | Med | 0.34 | 5.3 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API | ||
| CVE-2025-57730 | Med | 0.34 | 5.2 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature | ||
| CVE-2025-29904 | Med | 0.34 | 5.3 | 0.00 | Mar 12, 2025 | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible | ||
| CVE-2025-29903 | Med | 0.34 | 5.2 | 0.00 | Mar 12, 2025 | In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible | ||
| CVE-2024-56349 | Med | 0.34 | 5.3 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs | ||
| CVE-2024-50574 | Med | 0.34 | 5.3 | 0.01 | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | ||
| CVE-2024-47949 | Med | 0.34 | 4.9 | 0.23 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | ||
| CVE-2024-38505 | Med | 0.34 | 5.3 | 0.00 | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | ||
| CVE-2024-36375 | Med | 0.34 | 5.3 | 0.00 | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed | ||
| CVE-2024-28228 | Med | 0.34 | 5.3 | 0.00 | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | ||
| CVE-2024-24943 | Med | 0.34 | 5.3 | 0.00 | Feb 6, 2024 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | ||
| CVE-2023-41249 | Med | 0.34 | 4.6 | 0.53 | Aug 25, 2023 | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | ||
| CVE-2023-39261 | Med | 0.34 | 5.2 | 0.00 | Jul 26, 2023 | In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions | ||
| CVE-2023-34228 | Med | 0.34 | 5.3 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions | ||
| CVE-2023-34227 | Med | 0.34 | 5.3 | 0.01 | May 31, 2023 | In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks | ||
| CVE-2022-48481 | Med | 0.34 | 5.2 | 0.00 | Apr 28, 2023 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible | ||
| CVE-2022-48432 | Med | 0.34 | 5.2 | 0.00 | Mar 29, 2023 | In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed. | ||
| CVE-2022-48342 | Med | 0.34 | 5.2 | 0.00 | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents. | ||
| CVE-2022-46828 | Med | 0.34 | 5.2 | 0.00 | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | ||
| CVE-2021-37546 | Med | 0.34 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. | ||
| CVE-2021-25763 | Med | 0.34 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. | ||
| CVE-2021-25761 | Med | 0.34 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. | ||
| CVE-2019-18361 | Med | 0.34 | 5.3 | 0.00 | Oct 31, 2019 | JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution. | ||
| CVE-2024-39879 | Med | 0.33 | 5.0 | 0.00 | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings | ||
| CVE-2022-47896 | Med | 0.33 | 5.0 | 0.00 | Dec 22, 2022 | In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. | ||
| CVE-2019-19703 | Med | 0.33 | 6.1 | 0.01 | Dec 10, 2019 | In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. | ||
| CVE-2025-52877 | Med | 0.32 | 4.8 | 0.17 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible | ||
| CVE-2025-46433 | Med | 0.32 | 4.9 | 0.01 | Apr 25, 2025 | In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible | ||
| CVE-2025-31140 | Med | 0.32 | 4.6 | 0.27 | Mar 27, 2025 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page | ||
| CVE-2024-47948 | Med | 0.32 | 4.9 | 0.01 | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | ||
| CVE-2020-11938 | Med | 0.32 | 4.9 | 0.01 | Apr 22, 2020 | In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2. | ||
| CVE-2019-15035 | Med | 0.32 | 4.9 | 0.01 | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1. | ||
| CVE-2025-57727 | Med | 0.31 | 4.7 | 0.00 | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference | ||
| CVE-2025-54534 | Med | 0.31 | 4.8 | 0.01 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page | ||
| CVE-2025-52879 | Med | 0.31 | 4.8 | 0.01 | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible | ||
| CVE-2025-47853 | Med | 0.31 | 4.8 | 0.01 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible | ||
| CVE-2025-47852 | Med | 0.31 | 4.8 | 0.01 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible | ||
| CVE-2025-47851 | Med | 0.31 | 4.8 | 0.02 | May 20, 2025 | In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible | ||
| CVE-2023-34224 | Med | 0.31 | 4.8 | 0.00 | May 31, 2023 | In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible |
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
- risk 0.35cvss 5.3epss 0.01
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
- risk 0.35cvss 5.3epss 0.01
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
- risk 0.35cvss 5.3epss 0.01
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
- risk 0.35cvss 5.3epss 0.01
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
- risk 0.35cvss 5.3epss 0.01
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
- risk 0.35cvss 5.3epss 0.01
The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.
- risk 0.34cvss 5.3epss 0.00
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
- risk 0.34cvss 5.3epss 0.00
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
- risk 0.34cvss 5.2epss 0.00
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logs
- risk 0.34cvss 5.3epss 0.01
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
- risk 0.34cvss 4.9epss 0.23
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
- risk 0.34cvss 5.3epss 0.00
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
- risk 0.34cvss 5.3epss 0.00
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
- risk 0.34cvss 4.6epss 0.53
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions
- risk 0.34cvss 5.3epss 0.00
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
- risk 0.34cvss 5.2epss 0.00
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
- risk 0.34cvss 5.2epss 0.00
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
- risk 0.34cvss 5.2epss 0.00
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
- risk 0.34cvss 5.3epss 0.01
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
- risk 0.34cvss 5.3epss 0.01
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
- risk 0.34cvss 5.3epss 0.01
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
- risk 0.34cvss 5.3epss 0.00
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
- risk 0.33cvss 5.0epss 0.00
In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
- risk 0.33cvss 5.0epss 0.00
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
- risk 0.33cvss 6.1epss 0.01
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
- risk 0.32cvss 4.8epss 0.17
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
- risk 0.32cvss 4.9epss 0.01
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
- risk 0.32cvss 4.6epss 0.27
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
- risk 0.32cvss 4.9epss 0.01
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
- risk 0.32cvss 4.9epss 0.01
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
- risk 0.32cvss 4.9epss 0.01
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
- risk 0.31cvss 4.7epss 0.00
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible
- risk 0.31cvss 4.8epss 0.01
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible
- risk 0.31cvss 4.8epss 0.02
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible
- risk 0.31cvss 4.8epss 0.00
In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible
Page 8 of 13