Vulnerabilities > Jetbrains > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-16 CVE-2020-27628 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
network
low complexity
jetbrains
4.0
2020-11-16 CVE-2020-27626 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Youtrack
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
network
low complexity
jetbrains CWE-918
5.0
2020-11-16 CVE-2020-27625 Unspecified vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
network
low complexity
jetbrains
5.0
2020-11-16 CVE-2020-27624 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Youtrack
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
network
low complexity
jetbrains CWE-918
5.0
2020-11-16 CVE-2020-25210 Information Exposure vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
network
low complexity
jetbrains CWE-200
5.0
2020-11-16 CVE-2020-25209 Information Exposure vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
network
low complexity
jetbrains CWE-200
5.0
2020-11-16 CVE-2020-25013 Unspecified vulnerability in Jetbrains Toolbox
JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.
network
low complexity
jetbrains
5.0
2020-08-27 CVE-2020-24618 Unspecified vulnerability in Jetbrains Youtrack
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
network
low complexity
jetbrains
4.0
2020-08-08 CVE-2020-15831 Cross-site Scripting vulnerability in Jetbrains Teamcity
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
network
jetbrains CWE-79
4.3
2020-08-08 CVE-2020-15830 Cross-site Scripting vulnerability in Jetbrains Teamcity
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
network
jetbrains CWE-79
4.3