Vulnerabilities > Jetbrains > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-07-03 CVE-2019-9186 Exposure of Resource to Wrong Sphere vulnerability in Jetbrains Intellij Idea
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface).
network
low complexity
jetbrains CWE-668
critical
9.8
2019-07-03 CVE-2019-12867 Unspecified vulnerability in Jetbrains Youtrack
Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack.
network
low complexity
jetbrains
critical
9.8
2019-07-03 CVE-2019-12866 Authorization Bypass Through User-Controlled Key vulnerability in Jetbrains Youtrack
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack.
network
low complexity
jetbrains CWE-639
critical
9.8
2019-07-03 CVE-2019-12850 SQL Injection vulnerability in Jetbrains Youtrack
A query injection was possible in JetBrains YouTrack.
network
low complexity
jetbrains CWE-89
critical
9.8
2019-07-03 CVE-2019-10104 Unspecified vulnerability in Jetbrains Intellij Idea
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only.
network
low complexity
jetbrains
critical
9.8
2019-07-03 CVE-2019-10100 Code Injection vulnerability in Jetbrains Youtrack Integration
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection.
network
low complexity
jetbrains CWE-94
critical
9.8