CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command |
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots |
In JetBrains YouTrack before 2025.2.86935,
2025.2.87167,
2025.3.87341,
2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions |
In JetBrains YouTrack before 2025.2.86069,
2024.3.85077,
2025.1.86199 email spoofing via an administrative API was possible |
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible |
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible |
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible |
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible |
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible |
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions |
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible |
In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning |
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API |
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible |
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible |
In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible |
In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page |