Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2020-15819 JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. Youtrack 2020.2.10643+ Fix from $1,6002020-08-08 CRITICAL 9.8 CVE-2020-11796 In JetBrains Space through 2020-04-22, the password authentication implementation was insecure. Space after 2020-04-22 Fix from $2,3002020-04-22 HIGH 7.5 CVE-2020-11795 In JetBrains Space through 2020-04-22, the session timeout period was configured improperly. Space 2020-04-22+ Fix from $1,9502020-04-22 CRITICAL 9.8 CVE-2020-11690 In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases. Intellij Idea 2020.1+ Fix from $2,3002020-04-22 HIGH 7.5 CVE-2020-11685 In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. Goland 2019.3.2+ Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11687 In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages. Teamcity 2019.2.2+ Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11688 In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session. Teamcity 2019.2.1+ Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11691 In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible. Hub 2020.1.12099+ Fix from $1,9502020-04-22 HIGH 7.5 CVE-2020-11693 JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue. Youtrack 2020.1.659+ Fix from $1,9502020-04-22 MEDIUM 6.5 CVE-2020-11689 In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file. Teamcity 2019.2.1+ Fix from $1,6002020-04-22 MEDIUM 5.4 CVE-2020-11416 JetBrains Space through 2020-04-22 allows stored XSS in Chats. Space after 2020-04-22 Fix from $1,6002020-04-22 HIGH 7.5 CVE-2020-11694 In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. Pycharm No fix yet Fix from $1,9502020-04-10 HIGH 7.5 CVE-2020-7907 In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections. Scala 2019.2.1+ Fix from $1,9502020-02-21 HIGH 7.5 CVE-2020-7914 In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fi… Intellij Idea 2019.3.0+ Fix from $1,9502020-01-31 MEDIUM 6.1 CVE-2020-7911 In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS. Teamcity 2019.2.0+ Fix from $1,6002020-01-30 MEDIUM 6.1 CVE-2020-7913 JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description. Youtrack 2019.2.59309+ Fix from $1,6002020-01-30 MEDIUM 5.4 CVE-2020-7910 JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role. Teamcity 2019.2.0+ Fix from $1,6002020-01-30 MEDIUM 5.3 CVE-2020-7912 In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. Youtrack 2019.2.59309+ Fix from $1,6002020-01-30 HIGH 7.5 CVE-2020-7905 Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. Intellij Idea 2019.3.0+ Fix from $1,9502020-01-30 HIGH 7.5 CVE-2020-7906 In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in … Rider Mitigation only Fix from $1,9502020-01-30 HIGH 7.5 CVE-2020-7909 In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI. Teamcity 2019.1.5+ Fix from $1,9502020-01-30 HIGH 7.4 CVE-2020-7904 In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. Intellij Idea 2019.3.0+ Fix from $1,9502020-01-30 HIGH 7.5 CVE-2020-5207 In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or … Ktor 1.3.0+ Fix from $1,9502020-01-27 HIGH 7.5 CVE-2019-18412 JetBrains IDETalk plugin before version 193.4099.10 allows XXE Idetalk 193.4099.10+ Fix from $1,9502020-01-15 MEDIUM 5.4 CVE-2019-19389 JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. Ktor 1.2.6+ Fix from $1,6002019-12-26 MEDIUM 6.1 CVE-2019-19703 In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. Ktor after 1.2.6 Fix from $1,6002019-12-10 HIGH 7.3 CVE-2019-18368 In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. Toolbox 1.15.5666+ Fix from $1,9502019-10-31 MEDIUM 5.3 CVE-2019-18367 In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions. Teamcity 2019.1.2+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18369 In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. Youtrack 2019.2.55152+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18366 In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission. Teamcity 2019.1.2+ Fix from $1,6002019-10-31