Vulnerabilities > Jetbrains > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-12-04 CVE-2024-54154 Path Traversal vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
network
low complexity
jetbrains CWE-22
critical
9.8
2024-07-22 CVE-2024-41827 Insufficient Session Expiration vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
network
low complexity
jetbrains CWE-613
critical
9.8
2024-05-29 CVE-2024-36470 Missing Authentication for Critical Function vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
network
low complexity
jetbrains CWE-306
critical
9.8
2024-03-04 CVE-2024-27198 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
network
low complexity
jetbrains
critical
9.8
2024-02-06 CVE-2024-23917 Missing Authentication for Critical Function vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
network
low complexity
jetbrains CWE-306
critical
9.8
2023-12-21 CVE-2023-51655 Insufficient Verification of Data Authenticity vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
network
low complexity
jetbrains CWE-345
critical
9.8
2023-10-09 CVE-2023-45612 XXE vulnerability in Jetbrains Ktor
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
network
low complexity
jetbrains CWE-611
critical
9.8
2023-10-09 CVE-2023-45613 Unspecified vulnerability in Jetbrains Ktor
In JetBrains Ktor before 2.3.5 server certificates were not verified
network
low complexity
jetbrains
critical
9.1
2023-09-19 CVE-2023-42793 Missing Authentication for Critical Function vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
network
low complexity
jetbrains CWE-306
critical
9.8
2023-05-31 CVE-2023-34218 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
network
low complexity
jetbrains
critical
9.8