Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teamcity CRITICAL 9.8
CVE-2019-18364

In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

Fix: 2019.1.4+
Fix from $2,300 2019-10-31
Hub MEDIUM 5.3
CVE-2019-18360

In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.

Fix: 2019.1.11738+
Fix from $1,600 2019-10-31
Intellij Idea MEDIUM 5.3
CVE-2019-18361

JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.

Fix: 2019.2+
Fix from $1,600 2019-10-31
Mps MEDIUM 5.3
CVE-2019-18362

JetBrains MPS before 2019.2.2 exposed listening ports to the network.

Fix: 2019.2.2+
Fix from $1,600 2019-10-31
Teamcity MEDIUM 5.3
CVE-2019-18363

In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.

Fix: 2019.1.2+
Fix from $1,600 2019-10-31
Youtrack HIGH 8.8
CVE-2019-15040

JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.

Fix: 2019.1+
Fix from $1,950 2019-10-02
Resharper HIGH 7.3
CVE-2019-16407

JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.

Fix: 2019.2+
Fix from $1,950 2019-10-02
Teamcity HIGH 7.2
CVE-2019-15036

An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue w…

Mitigation only
Fix from $1,950 2019-10-02
Teamcity MEDIUM 6.1
CVE-2019-15037

An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2…

Mitigation only
Fix from $1,600 2019-10-02
Youtrack MEDIUM 6.1
CVE-2019-16171

In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.

Fix: after 2019.2.56594
Fix from $1,600 2019-10-02
Ktor CRITICAL 9.8
CVE-2019-12736

JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

Fix: after 1.1.5
Fix from $2,300 2019-10-02
Pycharm HIGH 7.5
CVE-2019-14958

JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could l…

Fix: 2019.2+
Fix from $1,950 2019-10-02
Toolbox MEDIUM 5.9
CVE-2019-14959

JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

Fix: 1.15.5605+
Fix from $1,600 2019-10-02
Ktor MEDIUM 5.3
CVE-2019-12737

UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.

Fix: after 1.1.5
Fix from $1,600 2019-10-02
Teamcity CRITICAL 9.8
CVE-2019-12157

In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.

Fix: 2018.2.5+
Fix from $2,300 2019-10-02
Upsource MEDIUM 5.3
CVE-2019-12156

Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions bef…

Fix: 2018.2.1290+
Fix from $1,600 2019-10-02
Youtrack MEDIUM 6.1
CVE-2019-15041

JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sp…

Fix: 2019.1.52545+
Fix from $1,600 2019-10-01
Teamcity HIGH 7.5
CVE-2019-15042

An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in T…

Mitigation only
Fix from $1,950 2019-10-01
Upsource MEDIUM 6.1
CVE-2019-14961

JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.

Fix: 2019.1.1412+
Fix from $1,600 2019-10-01
Rider HIGH 7.8
CVE-2019-14960

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

Fix: 2019.1.2+
Fix from $1,950 2019-10-01
Teamcity HIGH 7.5
CVE-2019-15038

An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in …

Mitigation only
Fix from $1,950 2019-10-01
Hub MEDIUM 5.3
CVE-2019-14955

In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was…

Fix: 2018.4.11436+
Fix from $1,600 2019-10-01
Vim MEDIUM 5.3
CVE-2019-14957

The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchron…

Fix: 0.52+
Fix from $1,600 2019-10-01
Youtrack MEDIUM 6.1
CVE-2019-14953

JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.

Fix: 2019.2.53938+
Fix from $1,600 2019-10-01
Teamcity CRITICAL 9.8
CVE-2019-15039EPSS 13%

An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.

No fix yet
Fix from $2,300 2019-10-01
Intellij Idea MEDIUM 5.9
CVE-2019-14954

JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.

Fix: 2019.2+
Fix from $1,600 2019-10-01
Youtrack MEDIUM 6.1
CVE-2019-14952

JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.

Fix: 2019.1.52584+
Fix from $1,600 2019-10-01
Teamcity MEDIUM 6.1
CVE-2019-15848

JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamC…

Patch available
Fix from $1,600 2019-09-05
Youtrack CRITICAL 9.8
CVE-2019-12852

An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.

Fix: 2018.4.49168+
Fix from $2,300 2019-07-03
Kotlin HIGH 8.1
CVE-2019-10101

JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM atta…

Fix: 1.3.30+
Fix from $1,950 2019-07-03