Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 472 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34221 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible
CVE-2023-34220 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2023-34219 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
CVE-2023-34218 1 Jetbrains 1 Teamcity 2024-11-21 N/A 9.1 CRITICAL
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
CVE-2022-48481 2 Apple, Jetbrains 2 Macos, Toolbox 2024-11-21 N/A 5.2 MEDIUM
In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
CVE-2022-48477 1 Jetbrains 1 Hub 2024-11-21 N/A 4.1 MEDIUM
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
CVE-2022-48476 1 Jetbrains 1 Ktor 2024-11-21 N/A 7.5 HIGH
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2022-48435 1 Jetbrains 1 Phpstorm 2024-11-21 N/A 3.3 LOW
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
CVE-2022-48433 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 6.1 MEDIUM
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
CVE-2022-48432 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 5.2 MEDIUM
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
CVE-2022-48431 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 4.5 MEDIUM
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
CVE-2022-48430 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 5.5 MEDIUM
In JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.
CVE-2022-48429 1 Jetbrains 1 Hub 2024-11-21 N/A 4.6 MEDIUM
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
CVE-2022-48428 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVE-2022-48427 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
CVE-2022-48426 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.6 MEDIUM
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
CVE-2022-48344 1 Jetbrains 1 Teamcity 2024-11-21 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-48343 1 Jetbrains 1 Teamcity 2024-11-21 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-48342 1 Jetbrains 1 Teamcity 2024-11-21 N/A 5.2 MEDIUM
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-46831 1 Jetbrains 1 Teamcity 2024-11-21 N/A 6.6 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.