Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Youtrack CRITICAL 9.1
CVE-2021-37549

In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

Fix: 2021.1.11111+
Fix from $2,300 2021-08-06
Rubymine HIGH 8.8
CVE-2021-37543

In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.

Fix: 2021.1.1+
Fix from $1,950 2021-08-06
Teamcity HIGH 7.5
CVE-2021-37545

In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.

Fix: 2021.1+
Fix from $1,950 2021-08-06
Teamcity HIGH 7.5
CVE-2021-37548

In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.

Fix: 2021.1+
Fix from $1,950 2021-08-06
Youtrack HIGH 7.5
CVE-2021-37550

In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

Fix: 2021.2.16363+
Fix from $1,950 2021-08-06
Youtrack HIGH 7.5
CVE-2021-37553

In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

Fix: 2021.2.16363+
Fix from $1,950 2021-08-06
Teamcity MEDIUM 6.1
CVE-2021-37542

In JetBrains TeamCity before 2020.2.3, XSS was possible.

Fix: 2020.2.3+
Fix from $1,600 2021-08-06
Youtrack MEDIUM 5.4
CVE-2021-37552

In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.

Fix: 2021.2.17925+
Fix from $1,600 2021-08-06
Teamcity MEDIUM 5.3
CVE-2021-37546

In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

Fix: 2021.1+
Fix from $1,600 2021-08-06
Teamcity MEDIUM 5.3
CVE-2021-37547

In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.

Fix: 2020.2.4+
Fix from $1,600 2021-08-06
Youtrack MEDIUM 5.3
CVE-2021-37551

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

Fix: 2021.2.16363+
Fix from $1,600 2021-08-06
Hub CRITICAL 9.8
CVE-2021-36209

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

Fix: 2021.1.13389+
Fix from $2,300 2021-08-06
Hub MEDIUM 6.5
CVE-2021-37540

In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.

Fix: 2021.1.13262+
Fix from $1,600 2021-08-06
Hub MEDIUM 6.1
CVE-2021-37541

In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

Fix: 2021.1.13402+
Fix from $1,600 2021-08-06
Webstorm CRITICAL 9.8
CVE-2021-31897

In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.

Fix: 2021.1+
Fix from $2,300 2021-05-11
Teamcity CRITICAL 9.8
CVE-2021-31914

In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.

Fix: 2020.2.4+
Fix from $2,300 2021-05-11
Teamcity CRITICAL 9.8
CVE-2021-31915

In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.

Fix: 2020.2.4+
Fix from $2,300 2021-05-11
Teamcity HIGH 8.8
CVE-2021-31912

In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.

Fix: 2020.2.3+
Fix from $1,950 2021-05-11
Upsource HIGH 7.5
CVE-2021-30482

In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

Fix: 2020.1.1883+
Fix from $1,950 2021-05-11
Webstorm HIGH 7.5
CVE-2021-31898

In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.

Fix: 2021.1+
Fix from $1,950 2021-05-11
Teamcity HIGH 7.5
CVE-2021-31910

In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.

Fix: 2020.2.3+
Fix from $1,950 2021-05-11
Teamcity HIGH 7.5
CVE-2021-31913

In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during GitHub SSO token exchange.

Fix: 2020.2.3+
Fix from $1,950 2021-05-11
Teamcity MEDIUM 6.1
CVE-2021-31911

In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.

Fix: 2020.2.3+
Fix from $1,600 2021-05-11
Teamcity CRITICAL 9.8
CVE-2021-31909

In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.

Fix: 2020.2.3+
Fix from $2,300 2021-05-11
Teamcity MEDIUM 5.4
CVE-2021-31908

In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.

Fix: 2020.2.3+
Fix from $1,600 2021-05-11
Teamcity MEDIUM 5.4
CVE-2021-3315

In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.

Fix: 2020.2.2+
Fix from $1,600 2021-05-11
Teamcity MEDIUM 5.3
CVE-2021-31907

In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.

Fix: 2020.2.2+
Fix from $1,600 2021-05-11
Code With Me HIGH 8.8
CVE-2021-31899

In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.

Fix: 2021.1+
Fix from $1,950 2021-05-11
Intellij Idea HIGH 7.8
CVE-2021-29263

In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.

Fix: 2020.3.3+
Fix from $1,950 2021-05-11
Pycharm HIGH 7.8
CVE-2021-30005

In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

Fix: 2020.3.4+
Fix from $1,950 2021-05-11