Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2020-04-22 CVE-2020-11796 Improper Authentication vulnerability in Jetbrains Space 20200422
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
network
low complexity
jetbrains CWE-287
7.5
2020-04-22 CVE-2020-11795 Insufficient Session Expiration vulnerability in Jetbrains Space 20200422
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
network
low complexity
jetbrains CWE-613
5.0
2020-04-22 CVE-2020-11693 Improper Input Validation vulnerability in Jetbrains Youtrack
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
network
low complexity
jetbrains CWE-20
5.0
2020-04-22 CVE-2020-11692 Incorrect Default Permissions vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
network
low complexity
jetbrains CWE-276
4.0
2020-04-22 CVE-2020-11691 Improper Input Validation vulnerability in Jetbrains HUB
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
network
low complexity
jetbrains CWE-20
5.0
2020-04-22 CVE-2020-11690 Unspecified vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
network
low complexity
jetbrains
7.5
2020-04-22 CVE-2020-11689 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
network
low complexity
jetbrains CWE-276
4.0
2020-04-22 CVE-2020-11688 Insufficient Session Expiration vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
network
low complexity
jetbrains CWE-613
5.0
2020-04-22 CVE-2020-11687 Information Exposure vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
network
low complexity
jetbrains CWE-200
5.0
2020-04-22 CVE-2020-11686 Information Exposure vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
network
low complexity
jetbrains CWE-200
4.0