Filtered by vendor Jetbrains Subscriptions
Total 359 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-24344 1 Jetbrains 1 Youtrack 2022-03-04 5.4 Medium
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
CVE-2022-24343 1 Jetbrains 1 Youtrack 2022-03-04 4.3 Medium
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
CVE-2022-24342 1 Jetbrains 1 Teamcity 2022-03-04 8.8 High
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
CVE-2022-24334 1 Jetbrains 1 Teamcity 2022-03-04 5.3 Medium
In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
CVE-2022-24341 1 Jetbrains 1 Teamcity 2022-03-04 7.5 High
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
CVE-2022-24335 1 Jetbrains 1 Teamcity 2022-03-04 8.1 High
JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.
CVE-2022-24339 1 Jetbrains 1 Teamcity 2022-03-04 5.4 Medium
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
CVE-2022-24338 1 Jetbrains 1 Teamcity 2022-03-04 6.1 Medium
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
CVE-2022-24330 1 Jetbrains 1 Teamcity 2022-03-04 6.1 Medium
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
CVE-2022-24328 1 Jetbrains 1 Hub 2022-03-04 6.5 Medium
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
CVE-2022-24327 1 Jetbrains 1 Hub 2022-03-04 7.5 High
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
CVE-2021-25758 1 Jetbrains 1 Intellij Idea 2021-12-10 7.8 High
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
CVE-2021-43202 1 Jetbrains 1 Teamcity 2021-12-01 9.8 Critical
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
CVE-2021-43189 2 Google, Jetbrains 2 Android, Youtrack Mobile 2021-11-15 7.3 High
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
CVE-2021-43188 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-15 7.3 High
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
CVE-2021-43187 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-12 5.3 Medium
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
CVE-2021-43185 1 Jetbrains 1 Youtrack 2021-11-12 9.8 Critical
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
CVE-2021-43184 1 Jetbrains 1 Youtrack 2021-11-12 5.4 Medium
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
CVE-2021-43192 2 Apple, Jetbrains 2 Iphone Os, Youtrack Mobile 2021-11-10 5.3 Medium
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
CVE-2021-43193 1 Jetbrains 1 Teamcity 2021-11-10 9.8 Critical
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.