Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Intellij Idea MEDIUM 6.7
CVE-2022-29813

In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

Fix: 2022.1+
Fix from $1,600 2022-04-28
Intellij Idea MEDIUM 6.7
CVE-2022-29815

In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

Fix: 2022.1+
Fix from $1,600 2022-04-28
Intellij Idea MEDIUM 6.1
CVE-2022-29817

In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible

Fix: 2022.1+
Fix from $1,600 2022-04-28
Intellij Idea MEDIUM 5.5
CVE-2022-28651

In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields

Fix: 2021.3.3+
Fix from $1,600 2022-04-05
Youtrack MEDIUM 5.4
CVE-2022-28649

In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

Fix: 2022.1.43563+
Fix from $1,600 2022-04-05
Youtrack MEDIUM 5.4
CVE-2022-28650

In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

Fix: 2022.1.43700+
Fix from $1,600 2022-04-05
Youtrack MEDIUM 5.4
CVE-2022-28648

In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered

Fix: 2022.1.43563+
Fix from $1,600 2022-04-05
Youtrack CRITICAL 9.8
CVE-2022-24442

JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

Fix: 2021.4.40426+
Fix from $2,300 2022-02-25
Hub CRITICAL 9.8
CVE-2022-25262

In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

Fix: 2022.1.14434+
Fix from $2,300 2022-02-25
Teamcity CRITICAL 9.8
CVE-2022-25263

JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.

Fix: 2021.2.3+
Fix from $2,300 2022-02-25
Hub CRITICAL 9.1
CVE-2022-25260

JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

Fix: 2021.1.14276+
Fix from $2,300 2022-02-25
Teamcity HIGH 7.5
CVE-2022-25264

In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

Fix: 2021.2.3+
Fix from $1,950 2022-02-25
Hub MEDIUM 6.1
CVE-2022-25259

JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.

Fix: 2021.1.14276+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 6.1
CVE-2022-25261

JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.

Fix: 2021.2.2+
Fix from $1,600 2022-02-25
Teamcity CRITICAL 9.8
CVE-2022-24340

In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

Fix: 2021.2.1+
Fix from $2,300 2022-02-25
Teamcity HIGH 8.8
CVE-2022-24342

In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

Fix: 2021.2.1+
Fix from $1,950 2022-02-25
Teamcity HIGH 8.1
CVE-2022-24335

JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.

Fix: 2021.2.1+
Fix from $1,950 2022-02-25
Intellij Idea HIGH 7.8
CVE-2022-24345

In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

Fix: 2021.2.4+
Fix from $1,950 2022-02-25
Intellij Idea HIGH 7.8
CVE-2022-24346

In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

Fix: 2021.3.1+
Fix from $1,950 2022-02-25
Teamcity HIGH 7.5
CVE-2022-24341

In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

Fix: 2021.2.1+
Fix from $1,950 2022-02-25
Teamcity MEDIUM 6.5
CVE-2022-24333

In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.

Fix: 2021.2+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 6.5
CVE-2022-24337

In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

Fix: 2021.2+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 6.1
CVE-2022-24338

JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.

Fix: 2021.2.1+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 5.4
CVE-2022-24339

JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.

Fix: 2021.2.1+
Fix from $1,600 2022-02-25
Youtrack MEDIUM 5.4
CVE-2022-24344

JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

Fix: 2021.4.31698+
Fix from $1,600 2022-02-25
Youtrack MEDIUM 5.4
CVE-2022-24347

JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

Fix: 2021.4.36872+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 5.3
CVE-2022-24332

In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

Fix: 2021.2+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 5.3
CVE-2022-24334

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

Fix: 2021.2.1+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 5.3
CVE-2022-24336

In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to the TeamCity server.

Fix: 2021.2.1+
Fix from $1,600 2022-02-25
Clion CRITICAL 9.8
CVE-2021-45977

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, Ph…

Mitigation only
Fix from $2,300 2022-02-25