Vulnerabilities > Jetbrains > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-08-12 CVE-2022-38180 Improper Authentication vulnerability in Jetbrains Ktor
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
network
low complexity
jetbrains CWE-287
6.5
2022-08-10 CVE-2022-38133 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
network
low complexity
jetbrains CWE-532
5.3
2022-07-20 CVE-2022-36321 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
network
low complexity
jetbrains CWE-532
6.5
2022-07-01 CVE-2022-34894 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
network
low complexity
jetbrains
5.3
2022-05-12 CVE-2022-29927 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
network
low complexity
jetbrains CWE-79
6.1
2022-05-12 CVE-2022-29928 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
network
low complexity
jetbrains CWE-532
4.9
2022-05-12 CVE-2022-29929 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
network
low complexity
jetbrains CWE-79
6.1
2022-05-12 CVE-2022-29930 Use of Insufficiently Random Values vulnerability in Jetbrains Ktor 2.0.0
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value.
network
low complexity
jetbrains CWE-330
4.9
2022-04-28 CVE-2022-29811 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
network
low complexity
jetbrains CWE-79
4.8
2022-04-28 CVE-2022-29813 Code Injection vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
local
low complexity
jetbrains CWE-94
6.7