Vulnerabilities > Jetbrains > High

DATE CVE VULNERABILITY TITLE RISK
2020-04-10 CVE-2020-11694 Insufficiently Protected Credentials vulnerability in Jetbrains Pycharm 2019.2.5/2019.3
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included.
network
low complexity
jetbrains CWE-522
7.5
2020-02-21 CVE-2020-7907 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Scala
In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.
network
low complexity
jetbrains CWE-319
7.5
2020-01-31 CVE-2020-7914 Unspecified vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network.
network
low complexity
jetbrains
7.5
2020-01-30 CVE-2020-7909 Insufficiently Protected Credentials vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
network
low complexity
jetbrains CWE-522
7.5
2020-01-30 CVE-2020-7906 Improper Verification of Cryptographic Signature vulnerability in Jetbrains Rider 2019.3.0
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer.
network
low complexity
jetbrains CWE-347
7.5
2020-01-30 CVE-2020-7905 Unspecified vulnerability in Jetbrains Intellij Idea
Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.
network
low complexity
jetbrains
7.5
2020-01-30 CVE-2020-7904 Improper Certificate Validation vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
network
high complexity
jetbrains CWE-295
7.4
2020-01-27 CVE-2020-5207 HTTP Request Smuggling vulnerability in Jetbrains Ktor
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
network
low complexity
jetbrains CWE-444
7.5
2020-01-15 CVE-2019-18412 XXE vulnerability in Jetbrains Idetalk
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
network
low complexity
jetbrains CWE-611
7.5
2019-10-31 CVE-2019-18368 Unspecified vulnerability in Jetbrains Toolbox
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
network
low complexity
jetbrains
7.3