U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): jetbrains
  • Search Type: Search All
There are 364 matching records.
Displaying matches 161 through 180.
Vuln ID Summary CVSS Severity
CVE-2021-43201

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

Published: November 09, 2021; 10:15:10 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43200

In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2021-43199

In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43198

In JetBrains TeamCity before 2021.1.2, stored XSS is possible.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2021-43197

In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 6.1 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2021-43196

In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 7.5 HIGH
V2.0: 5.0 MEDIUM
CVE-2021-43195

In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43194

In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43193

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2021-43192

In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43191

JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43190

In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43189

In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 7.3 HIGH
V2.0: 7.5 HIGH
CVE-2021-43188

In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 7.3 HIGH
V2.0: 7.5 HIGH
CVE-2021-43187

In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.3 MEDIUM
V2.0: 5.0 MEDIUM
CVE-2021-43186

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

Published: November 09, 2021; 10:15:09 AM -0500
V3.1: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2021-43185

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

Published: November 09, 2021; 10:15:08 AM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2021-43184

In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.

Published: November 09, 2021; 10:15:08 AM -0500
V3.1: 5.4 MEDIUM
V2.0: 3.5 LOW
CVE-2021-43183

In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

Published: November 09, 2021; 10:15:08 AM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2021-37554

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

Published: August 06, 2021; 10:15:08 AM -0400
V3.1: 4.3 MEDIUM
V2.0: 4.0 MEDIUM