Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2019-10-01 CVE-2019-15041 Open Redirect vulnerability in Jetbrains Youtrack
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
network
jetbrains CWE-601
5.8
2019-10-01 CVE-2019-15035 Information Exposure vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
low complexity
jetbrains CWE-200
4.0
2019-10-01 CVE-2019-15042 Improper Certificate Validation vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
low complexity
jetbrains CWE-295
5.0
2019-10-01 CVE-2019-14961 Cross-site Scripting vulnerability in Jetbrains Upsource
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
network
jetbrains CWE-79
4.3
2019-10-01 CVE-2019-15038 Unspecified vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
low complexity
jetbrains
5.0
2019-10-01 CVE-2019-14960 Untrusted Search Path vulnerability in Jetbrains Rider
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
local
low complexity
jetbrains CWE-426
4.6
2019-10-01 CVE-2019-14957 Insecure Storage of Sensitive Information vulnerability in Jetbrains VIM
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file.
network
low complexity
jetbrains CWE-922
5.0
2019-10-01 CVE-2019-14955 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains HUB
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
network
low complexity
jetbrains CWE-640
5.0
2019-10-01 CVE-2019-14953 Cross-site Scripting vulnerability in Jetbrains Youtrack
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
network
jetbrains CWE-79
4.3
2019-10-01 CVE-2019-15039 Path Traversal vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
jetbrains CWE-22
6.8