Filtered by vendor Jetbrains
Subscribe
Total
293 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-24344 | 1 Jetbrains | 1 Youtrack | 2022-03-03 | 3.5 LOW | 5.4 MEDIUM |
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. | |||||
CVE-2022-24343 | 1 Jetbrains | 1 Youtrack | 2022-03-03 | 4.0 MEDIUM | 4.3 MEDIUM |
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. | |||||
CVE-2022-24342 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 6.8 MEDIUM | 8.8 HIGH |
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. | |||||
CVE-2022-24334 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. | |||||
CVE-2022-24336 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server. | |||||
CVE-2022-24341 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 5.0 MEDIUM | 7.5 HIGH |
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user. | |||||
CVE-2022-24335 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 6.8 MEDIUM | 8.1 HIGH |
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC. | |||||
CVE-2022-24339 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 3.5 LOW | 5.4 MEDIUM |
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. | |||||
CVE-2022-24338 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 4.3 MEDIUM | 6.1 MEDIUM |
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. | |||||
CVE-2022-24330 | 1 Jetbrains | 1 Teamcity | 2022-03-03 | 5.8 MEDIUM | 6.1 MEDIUM |
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. | |||||
CVE-2022-24328 | 1 Jetbrains | 1 Hub | 2022-03-03 | 4.0 MEDIUM | 6.5 MEDIUM |
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. | |||||
CVE-2022-24327 | 1 Jetbrains | 1 Hub | 2022-03-03 | 5.0 MEDIUM | 7.5 HIGH |
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. | |||||
CVE-2020-15824 | 2 Jetbrains, Oracle | 3 Kotlin, Banking Extensibility Workbench, Communications Cloud Native Core Policy | 2022-03-03 | 6.5 MEDIUM | 8.8 HIGH |
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default. | |||||
CVE-2021-25758 | 1 Jetbrains | 1 Intellij Idea | 2021-12-10 | 4.6 MEDIUM | 7.8 HIGH |
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution. | |||||
CVE-2021-43202 | 1 Jetbrains | 1 Teamcity | 2021-12-01 | 7.5 HIGH | 9.8 CRITICAL |
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. | |||||
CVE-2021-43189 | 2 Google, Jetbrains | 2 Android, Youtrack Mobile | 2021-11-15 | 7.5 HIGH | 7.3 HIGH |
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. | |||||
CVE-2021-43188 | 2 Apple, Jetbrains | 2 Iphone Os, Youtrack Mobile | 2021-11-15 | 7.5 HIGH | 7.3 HIGH |
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. | |||||
CVE-2021-43187 | 2 Apple, Jetbrains | 2 Iphone Os, Youtrack Mobile | 2021-11-12 | 5.0 MEDIUM | 5.3 MEDIUM |
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. | |||||
CVE-2021-43185 | 1 Jetbrains | 1 Youtrack | 2021-11-12 | 7.5 HIGH | 9.8 CRITICAL |
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. | |||||
CVE-2021-43184 | 1 Jetbrains | 1 Youtrack | 2021-11-12 | 3.5 LOW | 5.4 MEDIUM |
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. |