Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-24331 In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. Teamcity 2021.4+ Fix from $2,3002022-02-25 HIGH 7.5 CVE-2022-24327 In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. Hub 2021.1.13890+ Fix from $1,9502022-02-25 MEDIUM 6.5 CVE-2022-24328 In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. Hub 2021.1.13956+ Fix from $1,6002022-02-25 MEDIUM 6.1 CVE-2022-24330 In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. Teamcity 2021.2.1+ Fix from $1,6002022-02-25 MEDIUM 5.3 CVE-2022-24329 In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. Kotlin 1.6.0+ Fix from $1,6002022-02-25 CRITICAL 9.8 CVE-2021-43202 In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. Teamcity 2021.1.3+ Fix from $2,3002021-11-30 HIGH 7.5 CVE-2021-43180 In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. Hub 2021.1.13690+ Fix from $1,9502021-11-09 HIGH 7.5 CVE-2021-43182 In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. Hub 2021.1.13415+ Fix from $1,9502021-11-09 MEDIUM 6.1 CVE-2021-43181 In JetBrains Hub before 2021.1.13690, stored XSS is possible. Hub 2021.1.13690+ Fix from $1,6002021-11-09 HIGH 7.5 CVE-2021-43203 In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. Ktor 1.6.4+ Fix from $1,9502021-11-09 MEDIUM 5.3 CVE-2021-43201 In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. Teamcity 2021.1.3+ Fix from $1,6002021-11-09 CRITICAL 9.8 CVE-2021-43193 In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. Teamcity 2021.1.2+ Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-43200 In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. Teamcity 2021.2+ Fix from $2,3002021-11-09 HIGH 7.5 CVE-2021-43196 In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. Teamcity 2021.1+ Fix from $1,9502021-11-09 HIGH 7.3 CVE-2021-43188 In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. Youtrack Mobile 2021.2+ Fix from $1,9502021-11-09 HIGH 7.3 CVE-2021-43189 In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. Youtrack Mobile 2021.2+ Fix from $1,9502021-11-09 MEDIUM 6.1 CVE-2021-43197 In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS. Teamcity 2021.1.2+ Fix from $1,6002021-11-09 MEDIUM 5.4 CVE-2021-43186 JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. Youtrack 2021.3.24402+ Fix from $1,6002021-11-09 MEDIUM 5.4 CVE-2021-43198 In JetBrains TeamCity before 2021.1.2, stored XSS is possible. Teamcity 2021.1.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43187 In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. Youtrack Mobile 2021.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43190 In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. Youtrack Mobile 2021.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43191 JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. Youtrack Mobile 2021.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43192 In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. Youtrack Mobile 2021.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43194 In JetBrains TeamCity before 2021.1.2, user enumeration was possible. Teamcity 2021.1.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43195 In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. Teamcity 2021.1.2+ Fix from $1,6002021-11-09 MEDIUM 5.3 CVE-2021-43199 In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient. Teamcity 2021.1.2.+ Fix from $1,6002021-11-09 CRITICAL 9.8 CVE-2021-43183 In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. Hub 2021.1.13690+ Fix from $2,3002021-11-09 CRITICAL 9.8 CVE-2021-43185 JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. Youtrack 2021.3.23639+ Fix from $2,3002021-11-09 MEDIUM 5.4 CVE-2021-43184 In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. Youtrack 2021.3.21051+ Fix from $1,6002021-11-09 CRITICAL 9.8 CVE-2021-37544 In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization. Teamcity 2020.2.4+ Fix from $2,3002021-08-06