Vulnerabilities > Jetbrains
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-23 | CVE-2022-48344 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process. | 6.1 |
2022-12-08 | CVE-2022-46824 | Classic Buffer Overflow vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible. | 7.8 |
2022-12-08 | CVE-2022-46825 | Inadequate Encryption Strength vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects. | 3.3 |
2022-12-08 | CVE-2022-46826 | Path Traversal vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability. | 5.5 |
2022-12-08 | CVE-2022-46827 | XXE vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible. | 5.5 |
2022-12-08 | CVE-2022-46828 | Unrestricted Upload of File with Dangerous Type vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | 7.8 |
2022-12-08 | CVE-2022-46829 | Improper Authentication vulnerability in Jetbrains Gateway In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented. | 8.8 |
2022-12-08 | CVE-2022-46830 | Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Teamcity 2022.10 In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. | 5.3 |
2022-12-08 | CVE-2022-46831 | Insecure Default Initialization of Resource vulnerability in Jetbrains Teamcity 2022.10 In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators. | 4.9 |
2022-11-18 | CVE-2022-45471 | Allocation of Resources Without Limits or Throttling vulnerability in Jetbrains HUB In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address | 7.5 |