Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Total 474 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47895 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 4.7 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
CVE-2022-46831 1 Jetbrains 1 Teamcity 2024-11-21 N/A 6.6 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVE-2022-46830 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.1 MEDIUM
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-46829 1 Jetbrains 1 Jetbrains Gateway 2024-11-21 N/A 7.1 HIGH
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
CVE-2022-46828 2 Apple, Jetbrains 2 Macos, Intellij Idea 2024-11-21 N/A 5.2 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVE-2022-46827 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 3.9 LOW
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVE-2022-46826 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 6.2 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
CVE-2022-46825 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 4.0 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
CVE-2022-46824 2 Apple, Jetbrains 2 Macos, Intellij Idea 2024-11-21 N/A 5.6 MEDIUM
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
CVE-2022-45471 1 Jetbrains 1 Hub 2024-11-21 N/A 3.5 LOW
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
CVE-2022-44646 1 Jetbrains 1 Teamcity 2024-11-21 N/A 2.2 LOW
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
CVE-2022-44624 1 Jetbrains 1 Teamcity 2024-11-21 N/A 6.5 MEDIUM
In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters
CVE-2022-44623 1 Jetbrains 1 Teamcity 2024-11-21 N/A 6.5 MEDIUM
In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settings
CVE-2022-44622 1 Jetbrains 1 Teamcity 2024-11-21 N/A 2.7 LOW
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
CVE-2022-40979 1 Jetbrains 1 Teamcity 2024-11-21 N/A 4.4 MEDIUM
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable
CVE-2022-40978 1 Jetbrains 1 Intellij Idea 2024-11-21 N/A 7.5 HIGH
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
CVE-2022-38180 1 Jetbrains 1 Ktor 2024-11-21 N/A 5.3 MEDIUM
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
CVE-2022-38179 1 Jetbrains 1 Ktor 2024-11-21 N/A 4.7 MEDIUM
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
CVE-2022-38133 1 Jetbrains 1 Teamcity 2024-11-21 N/A 3.2 LOW
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
CVE-2022-37396 1 Jetbrains 1 Rider 2024-11-21 N/A 4.1 MEDIUM
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution