Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kotlin HIGH 8.1
CVE-2019-10102

JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the b…

Fix: 1.1.0 / 1.3.30+
Fix from $1,950 2019-07-03
Kotlin HIGH 8.1
CVE-2019-10103

JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connectio…

Fix: 1.3.30+
Fix from $1,950 2019-07-03
Teamcity HIGH 7.5
CVE-2019-12841

Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.

Fix: 2018.2.2+
Fix from $1,950 2019-07-03
Teamcity MEDIUM 6.1
CVE-2019-12842

A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.

Fix: 2018.2.2+
Fix from $1,600 2019-07-03
Teamcity MEDIUM 6.1
CVE-2019-12843

A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 201…

Fix: 2018.2.3+
Fix from $1,600 2019-07-03
Teamcity MEDIUM 6.1
CVE-2019-12844

A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

Fix: 2018.2.3+
Fix from $1,600 2019-07-03
Teamcity MEDIUM 5.3
CVE-2019-12845

The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.…

Fix: 2018.2.3+
Fix from $1,600 2019-07-03
Intellij Idea CRITICAL 9.8
CVE-2019-9186

In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when t…

Fix: 2018.1.8 / 2018.2.8+
Fix from $2,300 2019-07-03
Intellij Idea CRITICAL 9.8
CVE-2019-9823

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of t…

Fix: 2018.1.8 / 2018.2.8+
Fix from $2,300 2019-07-03
Intellij Idea CRITICAL 9.8
CVE-2019-9873

In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the s…

Fix: 2019.1+
Fix from $2,300 2019-07-03
Intellij Idea HIGH 8.1
CVE-2019-9872

In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencr…

Fix: 2018.1.8 / 2018.2.8+
Fix from $1,950 2019-07-03
Youtrack Integration CRITICAL 9.8
CVE-2019-10100

In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an…

Fix: 1.8.1.3+
Fix from $2,300 2019-07-03
Intellij Idea CRITICAL 9.8
CVE-2019-10104

In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the defau…

Fix: 2018.1.8 / 2018.2.8+
Fix from $2,300 2019-07-03
Youtrack CRITICAL 9.8
CVE-2019-12850

A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.

Fix: 2018.4.49168+
Fix from $2,300 2019-07-03
Youtrack CRITICAL 9.8
CVE-2019-12866

An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed…

Fix: 2018.4.49168+
Fix from $2,300 2019-07-03
Youtrack CRITICAL 9.8
CVE-2019-12867

Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

Fix: 2018.4.49168+
Fix from $2,300 2019-07-03
Youtrack HIGH 8.8
CVE-2019-12851

A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

Fix: 2018.4.49852+
Fix from $1,950 2019-07-03
Hub HIGH 7.2
CVE-2019-12847

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only releva…

Fix: 2018.4.11298+
Fix from $1,950 2019-07-03
Dotpeek HIGH 7.8
CVE-2018-14878

JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as…

Fix: 2018.2+
Fix from $1,950 2018-08-13
Intellij Idea HIGH 7.5
CVE-2017-8316

IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code…

Fix: 2017.2.2+
Fix from $1,950 2018-08-03
Teamcity MEDIUM 5.0
CVE-2014-10002

Unspecified vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to obtain sensitive information via unknown vectors.

Fix: after 8.0
Fix from $1,600 2015-01-13