Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teamcity HIGH 7.5
CVE-2021-26310

In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.

Fix: 2020.2.2.85899+
Fix from $1,950 2021-05-11
Intellij Idea HIGH 7.5
CVE-2021-30006

In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

Fix: 2020.3.3+
Fix from $1,950 2021-05-11
Intellij Idea HIGH 7.5
CVE-2021-30504

In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.

Fix: 2021.1+
Fix from $1,950 2021-05-11
Hub HIGH 7.5
CVE-2021-31901

In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.

Fix: 2021.1.13079+
Fix from $1,950 2021-05-11
Youtrack HIGH 7.5
CVE-2021-31902

In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

Fix: 2020.6.6600+
Fix from $1,950 2021-05-11
Youtrack HIGH 7.5
CVE-2021-31905

In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

Fix: 2020.6.8801+
Fix from $1,950 2021-05-11
Youtrack MEDIUM 6.1
CVE-2021-31903

In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.

Fix: 2021.1.9819+
Fix from $1,600 2021-05-11
Teamcity MEDIUM 6.1
CVE-2021-31904

In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.

Fix: 2020.2.2+
Fix from $1,600 2021-05-11
Youtrack MEDIUM 5.4
CVE-2021-27733

In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.

Fix: 2020.6.6441+
Fix from $1,600 2021-05-11
Code With Me MEDIUM 5.3
CVE-2021-31900

In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.

Fix: 2021.1+
Fix from $1,600 2021-05-11
Phpstorm MEDIUM 5.3
CVE-2021-25764

In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.

Fix: 2020.3+
Fix from $1,600 2021-03-18
Youtrack CRITICAL 9.8
CVE-2021-25770

In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.

Fix: 2020.5.3123+
Fix from $2,300 2021-02-03
Youtrack HIGH 7.5
CVE-2021-25769

In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.

Fix: 2020.4.6808+
Fix from $1,950 2021-02-03
Teamcity HIGH 7.5
CVE-2021-25776

In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.

Fix: 2020.2+
Fix from $1,950 2021-02-03
Teamcity MEDIUM 6.1
CVE-2021-25773

JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.

Fix: 2020.2+
Fix from $1,600 2021-02-03
Youtrack MEDIUM 5.3
CVE-2021-25767

In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.

Fix: 2020.6.1767+
Fix from $1,600 2021-02-03
Youtrack MEDIUM 5.3
CVE-2021-25768

In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.

Fix: 2020.4.4701+
Fix from $1,600 2021-02-03
Teamcity MEDIUM 5.3
CVE-2021-25772

In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.

Fix: 2020.2.2+
Fix from $1,600 2021-02-03
Teamcity MEDIUM 5.3
CVE-2021-25777

In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.

Fix: 2020.2.1+
Fix from $1,600 2021-02-03
Teamcity MEDIUM 5.3
CVE-2021-25778

In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.

Fix: 2020.2.1+
Fix from $1,600 2021-02-03
Youtrack HIGH 8.8
CVE-2021-25765

In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.

Fix: 2020.4.4701+
Fix from $1,950 2021-02-03
Intellij Idea HIGH 7.8
CVE-2021-25758

In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.

Fix: 2020.3+
Fix from $1,950 2021-02-03
Teamcity HIGH 7.5
CVE-2020-35667

JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.

Fix: 2020.2.85695+
Fix from $1,950 2021-02-03
Hub MEDIUM 6.5
CVE-2021-25759

In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.

Fix: 2020.1.12629+
Fix from $1,600 2021-02-03
Hub MEDIUM 6.1
CVE-2021-25757

In JetBrains Hub before 2020.1.12629, an open redirect was possible.

Fix: 2020.1.12629+
Fix from $1,600 2021-02-03
Intellij Idea MEDIUM 5.3
CVE-2021-25756

In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.

Fix: 2020.2+
Fix from $1,600 2021-02-03
Hub MEDIUM 5.3
CVE-2021-25760

In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.

Fix: 2020.1.12669+
Fix from $1,600 2021-02-03
Ktor MEDIUM 5.3
CVE-2021-25761

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

Fix: 1.5.0+
Fix from $1,600 2021-02-03
Ktor MEDIUM 5.3
CVE-2021-25762

In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.

Fix: 1.4.3+
Fix from $1,600 2021-02-03
Ktor MEDIUM 5.3
CVE-2021-25763

In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.

Fix: 1.4.2+
Fix from $1,600 2021-02-03