Filtered by vendor Jetbrains Subscriptions
Total 381 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-34228 1 Jetbrains 1 Teamcity 2024-08-02 5.3 Medium
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
CVE-2023-34218 1 Jetbrains 1 Teamcity 2024-08-02 9.1 Critical
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
CVE-2023-34220 1 Jetbrains 1 Teamcity 2024-08-02 4.6 Medium
In JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possible
CVE-2024-36470 1 Jetbrains 1 Teamcity 2024-08-02 8.1 High
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
CVE-2024-35301 1 Jetbrains 1 Teamcity 2024-08-02 5.5 Medium
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
CVE-2024-35300 1 Jetbrains 1 Teamcity 2024-08-02 3.5 Low
In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
CVE-2024-35302 1 Jetbrains 1 Teamcity 2024-08-02 5.4 Medium
In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
CVE-2024-31138 1 Jetbrains 1 Teamcity 2024-08-02 4.6 Medium
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
CVE-2024-31135 1 Jetbrains 1 Teamcity 2024-08-02 6.1 Medium
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
CVE-2024-31136 1 Jetbrains 1 Teamcity 2024-08-02 7.4 High
In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter
CVE-2024-31137 1 Jetbrains 1 Teamcity 2024-08-02 6.8 Medium
In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration
CVE-2024-27198 1 Jetbrains 1 Teamcity 2024-08-02 9.8 Critical
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
CVE-2024-24940 1 Jetbrains 1 Intellij Idea 2024-08-01 2.8 Low
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
CVE-2024-24942 1 Jetbrains 1 Teamcity 2024-08-01 5.3 Medium
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
CVE-2024-24936 1 Jetbrains 1 Teamcity 2024-08-01 4.3 Medium
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
CVE-2024-24937 1 Jetbrains 1 Teamcity 2024-08-01 4.6 Medium
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible
CVE-2024-24941 1 Jetbrains 1 Intellij Idea 2024-08-01 6.1 Medium
In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL
CVE-2024-24943 1 Jetbrains 1 Toolbox 2024-08-01 5.3 Medium
In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image
CVE-2024-24939 1 Jetbrains 1 Rider 2024-08-01 3.3 Low
In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible
CVE-2024-23917 1 Jetbrains 1 Teamcity 2024-08-01 9.8 Critical
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible