Vulnerability index

Browse CVEs

531 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-18364 In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. Teamcity 2019.1.4+ Fix from $2,3002019-10-31 MEDIUM 5.3 CVE-2019-18360 In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery. Hub 2019.1.11738+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18361 JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution. Intellij Idea 2019.2+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18362 JetBrains MPS before 2019.2.2 exposed listening ports to the network. Mps 2019.2.2+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18363 In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances. Teamcity 2019.1.2+ Fix from $1,6002019-10-31 HIGH 8.8 CVE-2019-15040 JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page. Youtrack 2019.1+ Fix from $1,9502019-10-02 HIGH 7.3 CVE-2019-16407 JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability. Resharper 2019.2+ Fix from $1,9502019-10-02 HIGH 7.2 CVE-2019-15036 An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue w… Teamcity Mitigation only Fix from $1,9502019-10-02 MEDIUM 6.1 CVE-2019-15037 An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2… Teamcity Mitigation only Fix from $1,6002019-10-02 MEDIUM 6.1 CVE-2019-16171 In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page. Youtrack after 2019.2.56594 Fix from $1,6002019-10-02 CRITICAL 9.8 CVE-2019-12736 JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection. Ktor after 1.1.5 Fix from $2,3002019-10-02 HIGH 7.5 CVE-2019-14958 JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could l… Pycharm 2019.2+ Fix from $1,9502019-10-02 MEDIUM 5.9 CVE-2019-14959 JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. Toolbox 1.15.5605+ Fix from $1,6002019-10-02 MEDIUM 5.3 CVE-2019-12737 UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. Ktor after 1.1.5 Fix from $1,6002019-10-02 CRITICAL 9.8 CVE-2019-12157 In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. Teamcity 2018.2.5+ Fix from $2,3002019-10-02 MEDIUM 5.3 CVE-2019-12156 Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions bef… Upsource 2018.2.1290+ Fix from $1,6002019-10-02 MEDIUM 6.1 CVE-2019-15041 JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sp… Youtrack 2019.1.52545+ Fix from $1,6002019-10-01 HIGH 7.5 CVE-2019-15042 An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in T… Teamcity Mitigation only Fix from $1,9502019-10-01 MEDIUM 6.1 CVE-2019-14961 JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. Upsource 2019.1.1412+ Fix from $1,6002019-10-01 HIGH 7.8 CVE-2019-14960 JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. Rider 2019.1.2+ Fix from $1,9502019-10-01 HIGH 7.5 CVE-2019-15038 An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in … Teamcity Mitigation only Fix from $1,9502019-10-01 MEDIUM 5.3 CVE-2019-14955 In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was… Hub 2018.4.11436+ Fix from $1,6002019-10-01 MEDIUM 5.3 CVE-2019-14957 The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchron… Vim 0.52+ Fix from $1,6002019-10-01 MEDIUM 6.1 CVE-2019-14953 JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser. Youtrack 2019.2.53938+ Fix from $1,6002019-10-01 CRITICAL 9.8 CVE-2019-15039EPSS 13% An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1. Teamcity No fix yet Fix from $2,3002019-10-01 MEDIUM 5.9 CVE-2019-14954 JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection. Intellij Idea 2019.2+ Fix from $1,6002019-10-01 MEDIUM 6.1 CVE-2019-14952 JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. Youtrack 2019.1.52584+ Fix from $1,6002019-10-01 MEDIUM 6.1 CVE-2019-15848 JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamC… Teamcity Patch available Fix from $1,6002019-09-05 CRITICAL 9.8 CVE-2019-12852 An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168. Youtrack 2018.4.49168+ Fix from $2,3002019-07-03 HIGH 8.1 CVE-2019-10101 JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM atta… Kotlin 1.3.30+ Fix from $1,9502019-07-03