Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Youtrack MEDIUM 5.3
CVE-2024-28228

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

Fix: 2024.1.25893+
Fix from $1,600 2024-03-07
Teamcity MEDIUM 5.8
CVE-2024-28174

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

Fix: 2023.11.4+
Fix from $1,600 2024-03-06
Teamcity CRITICAL 9.8
CVE-2024-27198 KEVEPSS 100%

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Fix: 2023.11.4+
Fix from $2,300 2024-03-04
Teamcity HIGH 7.3
CVE-2024-27199 KEVEPSS 100%

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Fix: 2023.11.4+
Fix from $1,950 2024-03-04
Toolbox MEDIUM 5.5
CVE-2024-24943

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

Fix: 2.2+
Fix from $1,600 2024-02-06
Intellij Idea MEDIUM 5.3
CVE-2024-24941

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

Fix: 2023.3.3+
Fix from $1,600 2024-02-06
Teamcity MEDIUM 5.3
CVE-2024-24942EPSS 32%

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

Fix: 2023.11.3+
Fix from $1,600 2024-02-06
Teamcity MEDIUM 5.3
CVE-2024-24938

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

Fix: 2023.11.2+
Fix from $1,600 2024-02-06
Rider MEDIUM 5.3
CVE-2024-24939

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

Fix: 2023.3.3+
Fix from $1,600 2024-02-06
Teamcity CRITICAL 9.8
CVE-2024-23917EPSS 54%

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

Fix: 2023.11.3+
Fix from $2,300 2024-02-06
Teamcity MEDIUM 5.4
CVE-2024-24937

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

Fix: 2023.11.2+
Fix from $1,600 2024-02-06
Teamcity MEDIUM 5.3
CVE-2024-24936

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

Fix: 2023.11.2+
Fix from $1,600 2024-02-06
Youtrack MEDIUM 5.4
CVE-2024-22370

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

Fix: 2023.3.22666+
Fix from $1,600 2024-01-09
Intellij Idea CRITICAL 9.8
CVE-2023-51655

In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the p…

Fix: 2023.3.2+
Fix from $2,300 2023-12-21
Teamcity HIGH 8.8
CVE-2023-50870

In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible

Fix: 2023.11.1+
Fix from $1,950 2023-12-15
Ktor CRITICAL 9.8
CVE-2023-45612

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

Fix: 2.3.5+
Fix from $2,300 2023-10-09
Ktor CRITICAL 9.1
CVE-2023-45613

In JetBrains Ktor before 2.3.5 server certificates were not verified

Fix: 2.3.5+
Fix from $2,300 2023-10-09
Teamcity CRITICAL 9.8
CVE-2023-42793 KEVEPSS 100%

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

Fix: 2023.05.4+
Fix from $2,300 2023-09-19
Teamcity MEDIUM 5.4
CVE-2023-43566

In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration

Fix: 2023.05.4+
Fix from $1,600 2023-09-19
Teamcity MEDIUM 6.1
CVE-2023-41249EPSS 53%

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step

Fix: 2023.05.3+
Fix from $1,600 2023-08-25
Teamcity MEDIUM 6.1
CVE-2023-41250

In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration

Fix: 2023.05.3+
Fix from $1,600 2023-08-25
Teamcity MEDIUM 5.4
CVE-2023-41248

In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration

Fix: 2023.05.3+
Fix from $1,600 2023-08-25
Intellij Idea HIGH 7.8
CVE-2023-39261

In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions

Fix: 2023.2+
Fix from $1,950 2023-07-26
Teamcity HIGH 8.8
CVE-2023-39173

In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access

Fix: 2023.05.2+
Fix from $1,950 2023-07-25
Teamcity HIGH 7.5
CVE-2023-39174

In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

Fix: 2023.05.2+
Fix from $1,950 2023-07-25
Teamcity MEDIUM 6.1
CVE-2023-39175

In JetBrains TeamCity before 2023.05.2 reflected XSS via GitHub integration was possible

Fix: 2023.05.2+
Fix from $1,600 2023-07-25
Youtrack HIGH 7.3
CVE-2023-38068

In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

Fix: 2023.1.16597+
Fix from $1,950 2023-07-12
Teamcity MEDIUM 6.5
CVE-2023-38062

In JetBrains TeamCity before 2023.05.1 parameters of the "password" type could be shown in the UI in certain composite build configurations

Fix: 2023.05.1+
Fix from $1,600 2023-07-12
Teamcity MEDIUM 6.5
CVE-2023-38064

In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

Fix: 2023.05.1+
Fix from $1,600 2023-07-12
Teamcity MEDIUM 6.5
CVE-2023-38067

In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

Fix: 2023.05.1+
Fix from $1,600 2023-07-12