Vulnerabilities > Jetbrains > High

DATE CVE VULNERABILITY TITLE RISK
2019-07-03 CVE-2019-10101 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Kotlin
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
network
high complexity
jetbrains CWE-319
8.1
2019-07-03 CVE-2019-9872 Insufficiently Protected Credentials vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
high complexity
jetbrains CWE-522
8.1
2019-07-03 CVE-2019-12851 Cross-Site Request Forgery (CSRF) vulnerability in Jetbrains Youtrack
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack.
network
low complexity
jetbrains CWE-352
8.8
2019-07-03 CVE-2019-12847 Insufficiently Protected Credentials vulnerability in Jetbrains HUB
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user.
network
low complexity
jetbrains CWE-522
7.2
2018-08-13 CVE-2018-14878 Deserialization of Untrusted Data vulnerability in Jetbrains Dotpeek and Resharper Ultimate
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
local
low complexity
jetbrains CWE-502
7.8
2018-08-03 CVE-2017-8316 XXE vulnerability in Jetbrains Intellij Idea
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
network
low complexity
jetbrains CWE-611
7.5