Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 358 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-48476 1 Jetbrains 1 Ktor 2023-12-10 N/A 7.5 HIGH
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2023-34220 1 Jetbrains 1 Teamcity 2023-12-10 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2023-34221 1 Jetbrains 1 Teamcity 2023-12-10 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
CVE-2023-34218 1 Jetbrains 1 Teamcity 2023-12-10 N/A 9.8 CRITICAL
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
CVE-2023-34227 1 Jetbrains 1 Teamcity 2023-12-10 N/A 7.5 HIGH
In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks
CVE-2022-48344 1 Jetbrains 1 Teamcity 2023-12-10 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-48343 1 Jetbrains 1 Teamcity 2023-12-10 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-47896 1 Jetbrains 1 Intellij Idea 2023-12-10 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
CVE-2022-48342 1 Jetbrains 1 Teamcity 2023-12-10 N/A 9.8 CRITICAL
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-46829 1 Jetbrains 1 Jetbrains Gateway 2023-12-10 N/A 8.8 HIGH
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
CVE-2022-46826 1 Jetbrains 1 Intellij Idea 2023-12-10 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
CVE-2022-46827 1 Jetbrains 1 Intellij Idea 2023-12-10 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVE-2022-46824 2 Apple, Jetbrains 2 Macos, Intellij Idea 2023-12-10 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
CVE-2022-46830 1 Jetbrains 1 Teamcity 2023-12-10 N/A 5.3 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-46831 1 Jetbrains 1 Teamcity 2023-12-10 N/A 4.9 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVE-2022-46828 2 Apple, Jetbrains 2 Macos, Intellij Idea 2023-12-10 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVE-2022-45471 1 Jetbrains 1 Hub 2023-12-10 N/A 7.5 HIGH
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
CVE-2022-46825 1 Jetbrains 1 Intellij Idea 2023-12-10 N/A 3.3 LOW
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
CVE-2022-47895 1 Jetbrains 1 Intellij Idea 2023-12-10 N/A 7.5 HIGH
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
CVE-2022-40979 1 Jetbrains 1 Teamcity 2023-12-10 N/A 5.3 MEDIUM
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable