Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2025-04-17 CVE-2025-43014 Missing Critical Step in Authentication vulnerability in Jetbrains Toolbox
In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
network
low complexity
jetbrains CWE-304
6.5
2025-04-17 CVE-2025-43015 Insecure Default Initialization of Resource vulnerability in Jetbrains Rubymine
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
network
low complexity
jetbrains CWE-1188
6.5
2025-04-17 CVE-2025-42921 Improper Validation of Certificate with Host Mismatch vulnerability in Jetbrains Toolbox
In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
network
low complexity
jetbrains CWE-297
6.5
2025-04-17 CVE-2025-43013 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Toolbox
In JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possible
network
low complexity
jetbrains CWE-319
7.5
2025-01-21 CVE-2025-24456 Missing Authentication for Critical Function vulnerability in Jetbrains HUB
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
network
low complexity
jetbrains CWE-306
8.8
2025-01-21 CVE-2025-24457 Information Exposure Through Log Files vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
local
low complexity
jetbrains CWE-532
5.5
2025-01-21 CVE-2025-24458 Authentication Bypass by Spoofing vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
local
low complexity
jetbrains CWE-290
7.8
2025-01-21 CVE-2025-24459 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
network
low complexity
jetbrains CWE-79
6.1
2025-01-21 CVE-2025-24460 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
network
low complexity
jetbrains CWE-863
4.3
2025-01-21 CVE-2025-24461 Missing Authorization vulnerability in Jetbrains Teamcity 2024.12.1
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
network
low complexity
jetbrains CWE-862
6.5