Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 484 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24337 1 Jetbrains 1 Teamcity 2022-03-04 4.0 MEDIUM 6.5 MEDIUM
In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.
CVE-2022-25259 1 Jetbrains 1 Hub 2022-03-04 4.3 MEDIUM 6.1 MEDIUM
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
CVE-2022-24340 1 Jetbrains 1 Teamcity 2022-03-04 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
CVE-2022-24347 1 Jetbrains 1 Youtrack 2022-03-04 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
CVE-2022-24344 1 Jetbrains 1 Youtrack 2022-03-04 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
CVE-2022-24343 1 Jetbrains 1 Youtrack 2022-03-04 4.0 MEDIUM 4.3 MEDIUM
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
CVE-2022-24342 1 Jetbrains 1 Teamcity 2022-03-04 6.8 MEDIUM 8.8 HIGH
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
CVE-2022-24334 1 Jetbrains 1 Teamcity 2022-03-04 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
CVE-2022-24341 1 Jetbrains 1 Teamcity 2022-03-04 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
CVE-2022-24335 1 Jetbrains 1 Teamcity 2022-03-04 6.8 MEDIUM 8.1 HIGH
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
CVE-2022-24339 1 Jetbrains 1 Teamcity 2022-03-04 3.5 LOW 5.4 MEDIUM
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
CVE-2022-24338 1 Jetbrains 1 Teamcity 2022-03-04 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
CVE-2022-24330 1 Jetbrains 1 Teamcity 2022-03-04 5.8 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
CVE-2022-24328 1 Jetbrains 1 Hub 2022-03-04 4.0 MEDIUM 6.5 MEDIUM
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
CVE-2022-24327 1 Jetbrains 1 Hub 2022-03-04 5.0 MEDIUM 7.5 HIGH
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
CVE-2021-25758 1 Jetbrains 1 Intellij Idea 2021-12-10 4.6 MEDIUM 7.8 HIGH
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
CVE-2021-43202 1 Jetbrains 1 Teamcity 2021-12-01 7.5 HIGH 9.8 CRITICAL
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
CVE-2021-43189 2 Google, Jetbrains 2 Android, Youtrack Mobile 2021-11-15 7.5 HIGH 7.3 HIGH
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
CVE-2021-43188 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-15 7.5 HIGH 7.3 HIGH
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
CVE-2021-43187 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.