Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jetbrains Subscribe
Total 293 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-40979 1 Jetbrains 1 Teamcity 2022-09-26 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
CVE-2022-40978 1 Jetbrains 1 Intellij Idea 2022-09-21 N/A 7.8 HIGH
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
CVE-2022-38180 1 Jetbrains 1 Ktor 2022-08-16 N/A 6.5 MEDIUM
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
CVE-2022-38179 1 Jetbrains 1 Ktor 2022-08-16 N/A 6.1 MEDIUM
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
CVE-2022-38133 1 Jetbrains 1 Teamcity 2022-08-12 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
CVE-2022-37396 1 Jetbrains 1 Rider 2022-08-10 N/A 7.8 HIGH
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
CVE-2022-37009 1 Jetbrains 1 Intellij Idea 2022-08-03 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
CVE-2022-37010 1 Jetbrains 1 Intellij Idea 2022-08-03 N/A 3.3 LOW
In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was missed
CVE-2022-36321 1 Jetbrains 1 Teamcity 2022-07-27 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
CVE-2022-36322 1 Jetbrains 1 Teamcity 2022-07-27 N/A 8.8 HIGH
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
CVE-2021-25778 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
CVE-2021-37551 1 Jetbrains 1 Youtrack 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
CVE-2021-37546 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
CVE-2021-43183 1 Jetbrains 1 Hub 2022-07-12 7.5 HIGH 9.8 CRITICAL
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
CVE-2021-25759 1 Jetbrains 1 Hub 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
CVE-2021-25768 1 Jetbrains 1 Youtrack 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
CVE-2021-25755 1 Jetbrains 1 Code With Me 2022-07-12 1.9 LOW 2.5 LOW
In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic.
CVE-2021-30005 1 Jetbrains 1 Pycharm 2022-07-12 4.6 MEDIUM 7.8 HIGH
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
CVE-2021-43196 1 Jetbrains 1 Teamcity 2022-07-12 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
CVE-2021-25775 1 Jetbrains 1 Teamcity 2022-07-12 5.5 MEDIUM 3.8 LOW
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.