Filtered by vendor Jetbrains
Subscribe
Total
293 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-40979 | 1 Jetbrains | 1 Teamcity | 2022-09-26 | N/A | 5.3 MEDIUM |
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable | |||||
CVE-2022-40978 | 1 Jetbrains | 1 Intellij Idea | 2022-09-21 | N/A | 7.8 HIGH |
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking | |||||
CVE-2022-38180 | 1 Jetbrains | 1 Ktor | 2022-08-16 | N/A | 6.5 MEDIUM |
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases | |||||
CVE-2022-38179 | 1 Jetbrains | 1 Ktor | 2022-08-16 | N/A | 6.1 MEDIUM |
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack | |||||
CVE-2022-38133 | 1 Jetbrains | 1 Teamcity | 2022-08-12 | N/A | 5.3 MEDIUM |
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases | |||||
CVE-2022-37396 | 1 Jetbrains | 1 Rider | 2022-08-10 | N/A | 7.8 HIGH |
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution | |||||
CVE-2022-37009 | 1 Jetbrains | 1 Intellij Idea | 2022-08-03 | N/A | 7.8 HIGH |
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible | |||||
CVE-2022-37010 | 1 Jetbrains | 1 Intellij Idea | 2022-08-03 | N/A | 3.3 LOW |
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed | |||||
CVE-2022-36321 | 1 Jetbrains | 1 Teamcity | 2022-07-27 | N/A | 6.5 MEDIUM |
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases | |||||
CVE-2022-36322 | 1 Jetbrains | 1 Teamcity | 2022-07-27 | N/A | 8.8 HIGH |
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible | |||||
CVE-2021-25778 | 1 Jetbrains | 1 Teamcity | 2022-07-12 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly. | |||||
CVE-2021-37551 | 1 Jetbrains | 1 Youtrack | 2022-07-12 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | |||||
CVE-2021-37546 | 1 Jetbrains | 1 Teamcity | 2022-07-12 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. | |||||
CVE-2021-43183 | 1 Jetbrains | 1 Hub | 2022-07-12 | 7.5 HIGH | 9.8 CRITICAL |
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. | |||||
CVE-2021-25759 | 1 Jetbrains | 1 Hub | 2022-07-12 | 4.0 MEDIUM | 6.5 MEDIUM |
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user. | |||||
CVE-2021-25768 | 1 Jetbrains | 1 Youtrack | 2022-07-12 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. | |||||
CVE-2021-25755 | 1 Jetbrains | 1 Code With Me | 2022-07-12 | 1.9 LOW | 2.5 LOW |
In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic. | |||||
CVE-2021-30005 | 1 Jetbrains | 1 Pycharm | 2022-07-12 | 4.6 MEDIUM | 7.8 HIGH |
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS. | |||||
CVE-2021-43196 | 1 Jetbrains | 1 Teamcity | 2022-07-12 | 5.0 MEDIUM | 7.5 HIGH |
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. | |||||
CVE-2021-25775 | 1 Jetbrains | 1 Teamcity | 2022-07-12 | 5.5 MEDIUM | 3.8 LOW |
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. |