Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 396 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34225 1 Jetbrains 1 Teamcity 2024-02-28 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible
CVE-2023-34222 1 Jetbrains 1 Teamcity 2024-02-28 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible
CVE-2022-48432 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 8.8 HIGH
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
CVE-2022-48428 1 Jetbrains 1 Teamcity 2024-02-28 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVE-2022-45471 1 Jetbrains 1 Hub 2024-02-28 N/A 7.5 HIGH
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
CVE-2022-46828 2 Apple, Jetbrains 2 Macos, Intellij Idea 2024-02-28 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVE-2022-46825 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 3.3 LOW
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
CVE-2022-46826 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
CVE-2022-46830 1 Jetbrains 1 Teamcity 2024-02-28 N/A 5.3 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-48342 1 Jetbrains 1 Teamcity 2024-02-28 N/A 9.8 CRITICAL
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-48343 1 Jetbrains 1 Teamcity 2024-02-28 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-47896 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
CVE-2022-46829 1 Jetbrains 1 Jetbrains Gateway 2024-02-28 N/A 8.8 HIGH
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
CVE-2022-46827 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVE-2022-46824 2 Apple, Jetbrains 2 Macos, Intellij Idea 2024-02-28 N/A 7.8 HIGH
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
CVE-2022-47895 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 7.5 HIGH
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
CVE-2022-48344 1 Jetbrains 1 Teamcity 2024-02-28 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-46831 1 Jetbrains 1 Teamcity 2024-02-28 N/A 4.9 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVE-2022-36322 1 Jetbrains 1 Teamcity 2024-02-28 N/A 8.8 HIGH
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
CVE-2022-40978 1 Jetbrains 1 Intellij Idea 2024-02-28 N/A 7.8 HIGH
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking