Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2024-09-19 CVE-2024-47162 Insufficiently Protected Credentials vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
network
low complexity
jetbrains CWE-522
5.3
2024-09-16 CVE-2024-46970 Cross-site Scripting vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
network
low complexity
jetbrains CWE-79
6.1
2024-08-16 CVE-2024-43807 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page
network
low complexity
jetbrains CWE-79
5.4
2024-08-16 CVE-2024-43808 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin
network
low complexity
jetbrains CWE-79
5.4
2024-08-16 CVE-2024-43809 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page
network
low complexity
jetbrains CWE-79
6.1
2024-08-16 CVE-2024-43810 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin
network
low complexity
jetbrains CWE-79
5.4
2024-08-06 CVE-2024-43114 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
local
low complexity
jetbrains CWE-276
7.8
2024-07-22 CVE-2024-41824 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
network
low complexity
jetbrains CWE-532
6.5
2024-07-22 CVE-2024-41825 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
network
low complexity
jetbrains CWE-79
5.4
2024-07-22 CVE-2024-41826 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
network
low complexity
jetbrains CWE-79
4.8