| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. |
| In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. |
| In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient. |
| In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible. |
| In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing. |
| In JetBrains TeamCity before 2021.1.2, user enumeration was possible. |
| In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible. |
| In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. |
| JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. |
| In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. |
| In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. |
| In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. |
| In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. |
| In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. |
| In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. |
| In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. |
| As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N) |
| With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user accounts. |
| An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products. |