Vulnerabilities > Jetbrains > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-27 CVE-2022-48426 Cross-site Scripting vulnerability in Jetbrains Teamcity 2022.10.3
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
network
low complexity
jetbrains CWE-79
5.4
2023-03-27 CVE-2022-48429 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
network
low complexity
jetbrains CWE-79
5.4
2023-02-23 CVE-2022-48343 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
network
low complexity
jetbrains CWE-79
6.1
2023-02-23 CVE-2022-48344 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
network
low complexity
jetbrains CWE-79
6.1
2022-12-08 CVE-2022-46826 Path Traversal vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
local
low complexity
jetbrains CWE-22
5.5
2022-12-08 CVE-2022-46827 XXE vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
local
low complexity
jetbrains CWE-611
5.5
2022-12-08 CVE-2022-46830 Server-Side Request Forgery (SSRF) vulnerability in Jetbrains Teamcity 2022.10/2022.10.1
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
network
low complexity
jetbrains CWE-918
5.3
2022-12-08 CVE-2022-46831 Insecure Default Initialization of Resource vulnerability in Jetbrains Teamcity 2022.10/2022.10.1
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
network
low complexity
jetbrains CWE-1188
4.9
2022-11-03 CVE-2022-44622 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
network
low complexity
jetbrains
5.3
2022-11-03 CVE-2022-44646 Unspecified vulnerability in Jetbrains Teamcity
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
network
low complexity
jetbrains
5.3