Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jetbrains Subscribe
Total 293 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24344 1 Jetbrains 1 Youtrack 2022-03-03 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
CVE-2022-24343 1 Jetbrains 1 Youtrack 2022-03-03 4.0 MEDIUM 4.3 MEDIUM
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
CVE-2022-24342 1 Jetbrains 1 Teamcity 2022-03-03 6.8 MEDIUM 8.8 HIGH
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
CVE-2022-24334 1 Jetbrains 1 Teamcity 2022-03-03 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
CVE-2022-24336 1 Jetbrains 1 Teamcity 2022-03-03 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
CVE-2022-24341 1 Jetbrains 1 Teamcity 2022-03-03 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
CVE-2022-24335 1 Jetbrains 1 Teamcity 2022-03-03 6.8 MEDIUM 8.1 HIGH
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
CVE-2022-24339 1 Jetbrains 1 Teamcity 2022-03-03 3.5 LOW 5.4 MEDIUM
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
CVE-2022-24338 1 Jetbrains 1 Teamcity 2022-03-03 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
CVE-2022-24330 1 Jetbrains 1 Teamcity 2022-03-03 5.8 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
CVE-2022-24328 1 Jetbrains 1 Hub 2022-03-03 4.0 MEDIUM 6.5 MEDIUM
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
CVE-2022-24327 1 Jetbrains 1 Hub 2022-03-03 5.0 MEDIUM 7.5 HIGH
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
CVE-2020-15824 2 Jetbrains, Oracle 3 Kotlin, Banking Extensibility Workbench, Communications Cloud Native Core Policy 2022-03-03 6.5 MEDIUM 8.8 HIGH
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.
CVE-2021-25758 1 Jetbrains 1 Intellij Idea 2021-12-10 4.6 MEDIUM 7.8 HIGH
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
CVE-2021-43202 1 Jetbrains 1 Teamcity 2021-12-01 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
CVE-2021-43189 2 Google, Jetbrains 2 Android, Youtrack Mobile 2021-11-15 7.5 HIGH 7.3 HIGH
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
CVE-2021-43188 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-15 7.5 HIGH 7.3 HIGH
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
CVE-2021-43187 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
CVE-2021-43185 1 Jetbrains 1 Youtrack 2021-11-12 7.5 HIGH 9.8 CRITICAL
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
CVE-2021-43184 1 Jetbrains 1 Youtrack 2021-11-12 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.