Vulnerabilities > Jetbrains > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-01-21 | CVE-2025-24456 | Missing Authentication for Critical Function vulnerability in Jetbrains HUB In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping | 8.8 |
2025-01-21 | CVE-2025-24458 | Authentication Bypass by Spoofing vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | 7.8 |
2024-12-20 | CVE-2024-56351 | Insufficient Session Expiration vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles | 8.8 |
2024-12-20 | CVE-2024-56356 | XXE vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack | 7.1 |
2024-11-15 | CVE-2024-52555 | Unspecified vulnerability in Jetbrains Webstorm In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script | 7.8 |
2024-10-28 | CVE-2024-50574 | Unspecified vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | 7.5 |
2024-10-08 | CVE-2024-47948 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | 7.5 |
2024-10-08 | CVE-2024-47949 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | 7.5 |
2024-08-06 | CVE-2024-43114 | Incorrect Default Permissions vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions | 7.8 |
2024-07-22 | CVE-2024-41829 | Improper Authentication vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | 7.5 |