Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jetbrains Subscribe
Total 293 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15823 1 Jetbrains 1 Youtrack 2020-08-10 5.0 MEDIUM 7.5 HIGH
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
CVE-2020-15819 1 Jetbrains 1 Youtrack 2020-08-10 5.0 MEDIUM 5.3 MEDIUM
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
CVE-2020-15821 1 Jetbrains 1 Youtrack 2020-08-10 4.0 MEDIUM 6.5 MEDIUM
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
CVE-2020-15827 1 Jetbrains 1 Toolbox 2020-08-10 5.0 MEDIUM 7.5 HIGH
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
CVE-2020-15830 1 Jetbrains 1 Teamcity 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
CVE-2020-15831 1 Jetbrains 1 Teamcity 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
CVE-2020-11690 1 Jetbrains 1 Intellij Idea 2020-04-29 7.5 HIGH 9.8 CRITICAL
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
CVE-2020-11795 1 Jetbrains 1 Space 2020-04-29 5.0 MEDIUM 7.5 HIGH
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
CVE-2020-11796 1 Jetbrains 1 Space 2020-04-29 7.5 HIGH 9.8 CRITICAL
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
CVE-2020-11692 1 Jetbrains 1 Youtrack 2020-04-27 4.0 MEDIUM 2.7 LOW
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
CVE-2020-11416 1 Jetbrains 1 Space 2020-04-27 3.5 LOW 5.4 MEDIUM
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
CVE-2020-11687 1 Jetbrains 1 Teamcity 2020-04-27 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
CVE-2020-11688 1 Jetbrains 1 Teamcity 2020-04-27 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
CVE-2020-11689 1 Jetbrains 1 Teamcity 2020-04-27 4.0 MEDIUM 6.5 MEDIUM
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
CVE-2019-18412 1 Jetbrains 1 Idetalk 2020-02-06 5.0 MEDIUM 7.5 HIGH
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
CVE-2020-5207 1 Jetbrains 1 Ktor 2020-02-04 5.0 MEDIUM 7.5 HIGH
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
CVE-2020-7909 1 Jetbrains 1 Teamcity 2020-02-01 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
CVE-2020-7912 1 Jetbrains 1 Youtrack 2020-02-01 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
CVE-2020-7904 1 Jetbrains 1 Intellij Idea 2020-01-31 5.8 MEDIUM 7.4 HIGH
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
CVE-2020-7906 1 Jetbrains 1 Rider 2020-01-31 5.0 MEDIUM 7.5 HIGH
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.