Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2020-15819
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
Youtrack
2020.2.10643+
CRITICAL 9.8
CVE-2020-11796
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
Space
after 2020-04-22
HIGH 7.5
CVE-2020-11795
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
Space
2020-04-22+
CRITICAL 9.8
CVE-2020-11690
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
Intellij Idea
2020.1+
HIGH 7.5
CVE-2020-11685
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
Goland
2019.3.2+
HIGH 7.5
CVE-2020-11687
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
Teamcity
2019.2.2+
HIGH 7.5
CVE-2020-11688
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
Teamcity
2019.2.1+
HIGH 7.5
CVE-2020-11691
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
Hub
2020.1.12099+
HIGH 7.5
CVE-2020-11693
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
Youtrack
2020.1.659+
MEDIUM 6.5
CVE-2020-11689
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
Teamcity
2019.2.1+
MEDIUM 5.4
CVE-2020-11416
JetBrains Space through 2020-04-22 allows stored XSS in Chats.
Space
after 2020-04-22
HIGH 7.5
CVE-2020-11694
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
Pycharm
No fix yet
HIGH 7.5
CVE-2020-7907
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
Scala
2019.2.1+
HIGH 7.5
CVE-2020-7914
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fi…
Intellij Idea
2019.3.0+
MEDIUM 6.1
CVE-2020-7911
In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.
Teamcity
2019.2.0+
MEDIUM 6.1
CVE-2020-7913
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
Youtrack
2019.2.59309+
MEDIUM 5.4
CVE-2020-7910
JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.
Teamcity
2019.2.0+
MEDIUM 5.3
CVE-2020-7912
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
Youtrack
2019.2.59309+
HIGH 7.5
CVE-2020-7905
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.
Intellij Idea
2019.3.0+
HIGH 7.5
CVE-2020-7906
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in …
Rider
Mitigation only
HIGH 7.5
CVE-2020-7909
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
Teamcity
2019.1.5+
HIGH 7.4
CVE-2020-7904
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
Intellij Idea
2019.3.0+
HIGH 7.5
CVE-2020-5207
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or …
Ktor
1.3.0+
HIGH 7.5
CVE-2019-18412
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
Idetalk
193.4099.10+
MEDIUM 5.4
CVE-2019-19389
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Ktor
1.2.6+
MEDIUM 6.1
CVE-2019-19703
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
Ktor
after 1.2.6
HIGH 7.3
CVE-2019-18368
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
Toolbox
1.15.5666+
MEDIUM 5.3
CVE-2019-18367
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
Teamcity
2019.1.2+
MEDIUM 5.3
CVE-2019-18369
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
Youtrack
2019.2.55152+
MEDIUM 5.3
CVE-2019-18366
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
Teamcity
2019.1.2+