Vulnerabilities > Jetbrains

DATE CVE VULNERABILITY TITLE RISK
2020-01-15 CVE-2019-18412 XXE vulnerability in Jetbrains Idetalk
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
network
low complexity
jetbrains CWE-611
7.5
2019-12-26 CVE-2019-19389 Injection vulnerability in Jetbrains Ktor
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
network
low complexity
jetbrains CWE-74
5.4
2019-12-10 CVE-2019-19703 Open Redirect vulnerability in Jetbrains Ktor
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
network
low complexity
jetbrains CWE-601
6.1
2019-10-31 CVE-2019-18369 Incorrect Default Permissions vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
network
low complexity
jetbrains CWE-276
5.3
2019-10-31 CVE-2019-18368 Unspecified vulnerability in Jetbrains Toolbox
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
network
low complexity
jetbrains
7.3
2019-10-31 CVE-2019-18367 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
network
low complexity
jetbrains CWE-276
5.3
2019-10-31 CVE-2019-18366 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
network
low complexity
jetbrains CWE-276
5.3
2019-10-31 CVE-2019-18365 Improper Privilege Management vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
network
low complexity
jetbrains CWE-269
4.3
2019-10-31 CVE-2019-18364 Deserialization of Untrusted Data vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
network
low complexity
jetbrains CWE-502
critical
9.8
2019-10-31 CVE-2019-18363 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
network
low complexity
jetbrains
5.3