Vulnerabilities > Jetbrains
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-04-17 | CVE-2025-43014 | Missing Critical Step in Authentication vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation | 6.5 |
2025-04-17 | CVE-2025-43015 | Insecure Default Initialization of Resource vulnerability in Jetbrains Rubymine In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | 6.5 |
2025-04-17 | CVE-2025-42921 | Improper Validation of Certificate with Host Mismatch vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin | 6.5 |
2025-04-17 | CVE-2025-43013 | Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible | 7.5 |
2025-01-21 | CVE-2025-24456 | Missing Authentication for Critical Function vulnerability in Jetbrains HUB In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping | 8.8 |
2025-01-21 | CVE-2025-24457 | Information Exposure Through Log Files vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | 5.5 |
2025-01-21 | CVE-2025-24458 | Authentication Bypass by Spoofing vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | 7.8 |
2025-01-21 | CVE-2025-24459 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page | 6.1 |
2025-01-21 | CVE-2025-24460 | Incorrect Authorization vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool | 4.3 |
2025-01-21 | CVE-2025-24461 | Missing Authorization vulnerability in Jetbrains Teamcity 2024.12.1 In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint | 6.5 |