Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teamcity CRITICAL 9.8
CVE-2022-24331

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

Fix: 2021.4+
Fix from $2,300 2022-02-25
Hub HIGH 7.5
CVE-2022-24327

In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

Fix: 2021.1.13890+
Fix from $1,950 2022-02-25
Hub MEDIUM 6.5
CVE-2022-24328

In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.

Fix: 2021.1.13956+
Fix from $1,600 2022-02-25
Teamcity MEDIUM 6.1
CVE-2022-24330

In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.

Fix: 2021.2.1+
Fix from $1,600 2022-02-25
Kotlin MEDIUM 5.3
CVE-2022-24329

In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

Fix: 1.6.0+
Fix from $1,600 2022-02-25
Teamcity CRITICAL 9.8
CVE-2021-43202

In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.

Fix: 2021.1.3+
Fix from $2,300 2021-11-30
Hub HIGH 7.5
CVE-2021-43180

In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.

Fix: 2021.1.13690+
Fix from $1,950 2021-11-09
Hub HIGH 7.5
CVE-2021-43182

In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.

Fix: 2021.1.13415+
Fix from $1,950 2021-11-09
Hub MEDIUM 6.1
CVE-2021-43181

In JetBrains Hub before 2021.1.13690, stored XSS is possible.

Fix: 2021.1.13690+
Fix from $1,600 2021-11-09
Ktor HIGH 7.5
CVE-2021-43203

In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.

Fix: 1.6.4+
Fix from $1,950 2021-11-09
Teamcity MEDIUM 5.3
CVE-2021-43201

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

Fix: 2021.1.3+
Fix from $1,600 2021-11-09
Teamcity CRITICAL 9.8
CVE-2021-43193

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

Fix: 2021.1.2+
Fix from $2,300 2021-11-09
Teamcity CRITICAL 9.8
CVE-2021-43200

In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.

Fix: 2021.2+
Fix from $2,300 2021-11-09
Teamcity HIGH 7.5
CVE-2021-43196

In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

Fix: 2021.1+
Fix from $1,950 2021-11-09
Youtrack Mobile HIGH 7.3
CVE-2021-43188

In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

Fix: 2021.2+
Fix from $1,950 2021-11-09
Youtrack Mobile HIGH 7.3
CVE-2021-43189

In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

Fix: 2021.2+
Fix from $1,950 2021-11-09
Teamcity MEDIUM 6.1
CVE-2021-43197

In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.

Fix: 2021.1.2+
Fix from $1,600 2021-11-09
Youtrack MEDIUM 5.4
CVE-2021-43186

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

Fix: 2021.3.24402+
Fix from $1,600 2021-11-09
Teamcity MEDIUM 5.4
CVE-2021-43198

In JetBrains TeamCity before 2021.1.2, stored XSS is possible.

Fix: 2021.1.2+
Fix from $1,600 2021-11-09
Youtrack Mobile MEDIUM 5.3
CVE-2021-43187

In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.

Fix: 2021.2+
Fix from $1,600 2021-11-09
Youtrack Mobile MEDIUM 5.3
CVE-2021-43190

In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.

Fix: 2021.2+
Fix from $1,600 2021-11-09
Youtrack Mobile MEDIUM 5.3
CVE-2021-43191

JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.

Fix: 2021.2+
Fix from $1,600 2021-11-09
Youtrack Mobile MEDIUM 5.3
CVE-2021-43192

In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.

Fix: 2021.2+
Fix from $1,600 2021-11-09
Teamcity MEDIUM 5.3
CVE-2021-43194

In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

Fix: 2021.1.2+
Fix from $1,600 2021-11-09
Teamcity MEDIUM 5.3
CVE-2021-43195

In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.

Fix: 2021.1.2+
Fix from $1,600 2021-11-09
Teamcity MEDIUM 5.3
CVE-2021-43199

In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

Fix: 2021.1.2.+
Fix from $1,600 2021-11-09
Hub CRITICAL 9.8
CVE-2021-43183

In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

Fix: 2021.1.13690+
Fix from $2,300 2021-11-09
Youtrack CRITICAL 9.8
CVE-2021-43185

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

Fix: 2021.3.23639+
Fix from $2,300 2021-11-09
Youtrack MEDIUM 5.4
CVE-2021-43184

In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.

Fix: 2021.3.21051+
Fix from $1,600 2021-11-09
Teamcity CRITICAL 9.8
CVE-2021-37544

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

Fix: 2020.2.4+
Fix from $2,300 2021-08-06