Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2023-02-23 CVE-2022-48344 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
network
low complexity
jetbrains CWE-79
6.1
2022-12-22 CVE-2022-47895 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
network
low complexity
jetbrains CWE-319
7.5
2022-12-22 CVE-2022-47896 Code Injection vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
local
low complexity
jetbrains CWE-94
7.8
2022-12-08 CVE-2022-46824 Classic Buffer Overflow vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
local
low complexity
jetbrains CWE-120
7.8
2022-12-08 CVE-2022-46825 Inadequate Encryption Strength vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
local
low complexity
jetbrains CWE-326
3.3
2022-12-08 CVE-2022-46826 Path Traversal vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
local
low complexity
jetbrains CWE-22
5.5
2022-12-08 CVE-2022-46827 XXE vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
local
low complexity
jetbrains CWE-611
5.5
2022-12-08 CVE-2022-46828 Unrestricted Upload of File with Dangerous Type vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
local
low complexity
jetbrains CWE-434
7.8
2022-12-08 CVE-2022-46829 Improper Authentication vulnerability in Jetbrains Gateway
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
network
low complexity
jetbrains CWE-287
8.8
2022-12-08 CVE-2022-46830 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Teamcity 2022.10/2022.10.1
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
network
low complexity
jetbrains CWE-918
5.3