Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 358 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25264 1 Jetbrains 1 Teamcity 2023-12-10 5.0 MEDIUM 7.5 HIGH
In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
CVE-2022-29928 1 Jetbrains 1 Teamcity 2023-12-10 4.0 MEDIUM 4.9 MEDIUM
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
CVE-2022-29811 1 Jetbrains 1 Hub 2023-12-10 3.5 LOW 4.8 MEDIUM
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
CVE-2022-24345 1 Jetbrains 1 Intellij Idea 2023-12-10 4.6 MEDIUM 7.8 HIGH
In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.
CVE-2022-29819 1 Jetbrains 1 Intellij Idea 2023-12-10 4.4 MEDIUM 7.7 HIGH
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
CVE-2022-24442 1 Jetbrains 1 Youtrack 2023-12-10 7.5 HIGH 9.8 CRITICAL
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2022-28651 1 Jetbrains 1 Intellij Idea 2023-12-10 2.1 LOW 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
CVE-2022-25262 1 Jetbrains 1 Hub 2023-12-10 7.5 HIGH 9.8 CRITICAL
In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
CVE-2022-29929 1 Jetbrains 1 Teamcity 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
CVE-2022-29814 1 Jetbrains 1 Intellij Idea 2023-12-10 4.4 MEDIUM 7.7 HIGH
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
CVE-2022-29812 1 Jetbrains 1 Intellij Idea 2023-12-10 2.1 LOW 2.3 LOW
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
CVE-2022-29927 1 Jetbrains 1 Teamcity 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
CVE-2022-29813 1 Jetbrains 1 Intellij Idea 2023-12-10 4.6 MEDIUM 6.7 MEDIUM
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
CVE-2022-29820 1 Jetbrains 1 Pycharm 2023-12-10 3.3 LOW 3.5 LOW
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
CVE-2022-34894 1 Jetbrains 1 Hub 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
CVE-2022-25263 1 Jetbrains 1 Teamcity 2023-12-10 7.5 HIGH 9.8 CRITICAL
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
CVE-2022-24338 1 Jetbrains 1 Teamcity 2023-12-10 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
CVE-2022-24336 1 Jetbrains 1 Teamcity 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.
CVE-2022-29816 1 Jetbrains 1 Intellij Idea 2023-12-10 2.1 LOW 3.2 LOW
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
CVE-2022-24332 1 Jetbrains 1 Teamcity 2023-12-10 5.0 MEDIUM 5.3 MEDIUM
In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.