Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Youtrack MEDIUM 5.3
CVE-2021-25766

In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.

Fix: 2020.4.4701+
Fix from $1,600 2021-02-03
Youtrack MEDIUM 5.3
CVE-2020-25208

In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.

Fix: 2020.4.4701+
Fix from $1,600 2021-02-03
Kotlin MEDIUM 5.3
CVE-2020-29582

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such…

Fix: 2.1.0+
Fix from $1,600 2021-02-03
Ideavim HIGH 7.5
CVE-2020-27623

JetBrains IdeaVim before version 0.58 might have caused an information leak in limited circumstances.

Fix: 0.58+
Fix from $1,950 2020-11-16
Teamcity MEDIUM 6.1
CVE-2020-27627

JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.

Fix: 2020.1.2+
Fix from $1,600 2020-11-16
Intellij Idea MEDIUM 5.3
CVE-2020-27622

In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.

Fix: 2020.2+
Fix from $1,600 2020-11-16
Ktor MEDIUM 6.5
CVE-2020-26129

In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.

Fix: 1.4.1+
Fix from $1,600 2020-11-16
Youtrack MEDIUM 5.3
CVE-2020-27624

JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.

Fix: 2020.3.888+
Fix from $1,600 2020-11-16
Youtrack MEDIUM 5.3
CVE-2020-27625

In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.

Fix: 2020.3.888+
Fix from $1,600 2020-11-16
Youtrack MEDIUM 5.3
CVE-2020-27626

JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.

Fix: 2020.3.5333+
Fix from $1,600 2020-11-16
Teamcity MEDIUM 5.3
CVE-2020-27629

In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.

Fix: 2020.1.5+
Fix from $1,600 2020-11-16
Toolbox CRITICAL 9.8
CVE-2020-25207

JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.

Fix: 1.18+
Fix from $2,300 2020-11-16
Toolbox HIGH 7.5
CVE-2020-25013

JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.

Fix: 1.18+
Fix from $1,950 2020-11-16
Youtrack HIGH 7.5
CVE-2020-25209

In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

Fix: 2020.3.6638+
Fix from $1,950 2020-11-16
Youtrack MEDIUM 5.3
CVE-2020-25210

In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.

Fix: 2020.3.7955+
Fix from $1,600 2020-11-16
Youtrack HIGH 7.3
CVE-2020-15822

In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

Fix: 2020.2.10514+
Fix from $1,950 2020-10-19
Youtrack MEDIUM 6.5
CVE-2020-24618

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve…

Fix: 2019.1.65514 / 2019.2.65515+
Fix from $1,600 2020-08-27
Kotlin HIGH 8.8
CVE-2020-15824

In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege e…

Patch available
Fix from $1,950 2020-08-08
Teamcity HIGH 8.8
CVE-2020-15825

In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.

Fix: 2020.1+
Fix from $1,950 2020-08-08
Youtrack HIGH 7.5
CVE-2020-15823

JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

Fix: 2020.2.8873+
Fix from $1,950 2020-08-08
Toolbox HIGH 7.5
CVE-2020-15827

In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.

Fix: 1.17.6856+
Fix from $1,950 2020-08-08
Youtrack MEDIUM 6.5
CVE-2020-15821

In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

Fix: 2020.2.6881+
Fix from $1,600 2020-08-08
Teamcity MEDIUM 6.5
CVE-2020-15828

In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.

Fix: 2020.1.1+
Fix from $1,600 2020-08-08
Teamcity MEDIUM 6.1
CVE-2020-15830

JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.

Fix: 2019.2.3+
Fix from $1,600 2020-08-08
Teamcity MEDIUM 6.1
CVE-2020-15831

JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.

Fix: 2019.2.3+
Fix from $1,600 2020-08-08
Youtrack MEDIUM 5.3
CVE-2020-15820

In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.

Fix: 2020.2.6881+
Fix from $1,600 2020-08-08
Teamcity MEDIUM 5.3
CVE-2020-15829

In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

Fix: 2019.2.3+
Fix from $1,600 2020-08-08
Youtrack HIGH 8.8
CVE-2020-15817

In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.

Fix: 2020.1.1331+
Fix from $1,950 2020-08-08
Upsource HIGH 7.5
CVE-2019-19704

In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.

Fix: 2020.1+
Fix from $1,950 2020-08-08
Youtrack MEDIUM 5.3
CVE-2020-15818

In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.

Fix: 2020.2.8527+
Fix from $1,600 2020-08-08