Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Youtrack MEDIUM 5.3
CVE-2020-15819

JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.

Fix: 2020.2.10643+
Fix from $1,600 2020-08-08
Space CRITICAL 9.8
CVE-2020-11796

In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.

Fix: after 2020-04-22
Fix from $2,300 2020-04-22
Space HIGH 7.5
CVE-2020-11795

In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.

Fix: 2020-04-22+
Fix from $1,950 2020-04-22
Intellij Idea CRITICAL 9.8
CVE-2020-11690

In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.

Fix: 2020.1+
Fix from $2,300 2020-04-22
Goland HIGH 7.5
CVE-2020-11685

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

Fix: 2019.3.2+
Fix from $1,950 2020-04-22
Teamcity HIGH 7.5
CVE-2020-11687

In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.

Fix: 2019.2.2+
Fix from $1,950 2020-04-22
Teamcity HIGH 7.5
CVE-2020-11688

In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.

Fix: 2019.2.1+
Fix from $1,950 2020-04-22
Hub HIGH 7.5
CVE-2020-11691

In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.

Fix: 2020.1.12099+
Fix from $1,950 2020-04-22
Youtrack HIGH 7.5
CVE-2020-11693

JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.

Fix: 2020.1.659+
Fix from $1,950 2020-04-22
Teamcity MEDIUM 6.5
CVE-2020-11689

In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.

Fix: 2019.2.1+
Fix from $1,600 2020-04-22
Space MEDIUM 5.4
CVE-2020-11416

JetBrains Space through 2020-04-22 allows stored XSS in Chats.

Fix: after 2020-04-22
Fix from $1,600 2020-04-22
Pycharm HIGH 7.5
CVE-2020-11694

In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.

No fix yet
Fix from $1,950 2020-04-10
Scala HIGH 7.5
CVE-2020-7907

In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

Fix: 2019.2.1+
Fix from $1,950 2020-02-21
Intellij Idea HIGH 7.5
CVE-2020-7914

In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fi…

Fix: 2019.3.0+
Fix from $1,950 2020-01-31
Teamcity MEDIUM 6.1
CVE-2020-7911

In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.

Fix: 2019.2.0+
Fix from $1,600 2020-01-30
Youtrack MEDIUM 6.1
CVE-2020-7913

JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.

Fix: 2019.2.59309+
Fix from $1,600 2020-01-30
Teamcity MEDIUM 5.4
CVE-2020-7910

JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.

Fix: 2019.2.0+
Fix from $1,600 2020-01-30
Youtrack MEDIUM 5.3
CVE-2020-7912

In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

Fix: 2019.2.59309+
Fix from $1,600 2020-01-30
Intellij Idea HIGH 7.5
CVE-2020-7905

Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

Fix: 2019.3.0+
Fix from $1,950 2020-01-30
Rider HIGH 7.5
CVE-2020-7906

In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in …

Mitigation only
Fix from $1,950 2020-01-30
Teamcity HIGH 7.5
CVE-2020-7909

In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

Fix: 2019.1.5+
Fix from $1,950 2020-01-30
Intellij Idea HIGH 7.4
CVE-2020-7904

In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

Fix: 2019.3.0+
Fix from $1,950 2020-01-30
Ktor HIGH 7.5
CVE-2020-5207

In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or …

Fix: 1.3.0+
Fix from $1,950 2020-01-27
Idetalk HIGH 7.5
CVE-2019-18412

JetBrains IDETalk plugin before version 193.4099.10 allows XXE

Fix: 193.4099.10+
Fix from $1,950 2020-01-15
Ktor MEDIUM 5.4
CVE-2019-19389

JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.

Fix: 1.2.6+
Fix from $1,600 2019-12-26
Ktor MEDIUM 6.1
CVE-2019-19703

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.

Fix: after 1.2.6
Fix from $1,600 2019-12-10
Toolbox HIGH 7.3
CVE-2019-18368

In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

Fix: 1.15.5666+
Fix from $1,950 2019-10-31
Teamcity MEDIUM 5.3
CVE-2019-18367

In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

Fix: 2019.1.2+
Fix from $1,600 2019-10-31
Youtrack MEDIUM 5.3
CVE-2019-18369

In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

Fix: 2019.2.55152+
Fix from $1,600 2019-10-31
Teamcity MEDIUM 5.3
CVE-2019-18366

In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.

Fix: 2019.1.2+
Fix from $1,600 2019-10-31