Filters

Jetbrains TeamcityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirati…

First published (updated )

CVE-2024-37051GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and…

First published (updated )

Jetbrains TeamcityJetBrains TeamCity Authentication Bypass Vulnerability

EPSS
97.21%
First published (updated )

SolarWinds Access Rights ManagerSolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution

First published (updated )

SolarWinds Access Rights ManagerSolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability

EPSS
0.06%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

SolarWinds Access Rights ManagerSolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability

EPSS
0.06%
First published (updated )

SolarWinds Access Rights ManagerSolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability

EPSS
0.06%
First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

EPSS
0.09%
First published (updated )

JetBrains IntelliJ IDEAIn JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via…

First published (updated )

JetBrains KtorIn JetBrains Ktor before 2.3.5 server certificates were not verified

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

JetBrains KtorXEE

First published (updated )

Jetbrains TeamcityJetBrains TeamCity Authentication Bypass Vulnerability

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions w…

First published (updated )

JetBrains HubSSRF

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jetbrains YoutrackCode Injection

First published (updated )

JetBrains HubSSRF

First published (updated )

JetBrains HubIn JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

First published (updated )

Jetbrains TeamcityOS Command Injection, Command Injection

First published (updated )

JetBrains IntelliJ IDEAJetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 R…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jetbrains TeamcityXEE

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.

First published (updated )

JetBrains HubIn JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is pos…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jetbrains TeamcityIn JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insuff…

First published (updated )

Jetbrains YoutrackJetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

First published (updated )

Jetbrains YoutrackIn JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

First published (updated )

JetBrains HubIn JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

JetBrains WebStormIn JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untru…

First published (updated )

Jetbrains TeamcityOS Command Injection, Command Injection

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was po…

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possi…

First published (updated )

Jetbrains YoutrackCode Injection

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jetbrains ToolboxJetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol …

First published (updated )

JetBrains SpaceIn JetBrains Space through 2020-04-22, the password authentication implementation was insecure.

First published (updated )

JetBrains IntelliJ IDEAIn JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host …

First published (updated )

Jetbrains TeamcityIn JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote …

First published (updated )

JetBrains UpSourceInput Validation

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

JetBrains KtorCommand Injection

First published (updated )

Jetbrains TeamcityOS Command Injection

First published (updated )

Jetbrains TeamcityPath Traversal

First published (updated )

Jetbrains YoutrackSSRF

First published (updated )

JetBrains IntelliJ IDEAIn several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for T…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

JetBrains IntelliJ IDEAIn several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads …

First published (updated )

JetBrains IntelliJ IDEAIn several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default settin…

First published (updated )

Jetbrains YoutrackAn Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was po…

First published (updated )

Jetbrains YoutrackCertain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The is…

First published (updated )

Jetbrains YoutrackSQL Injection

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203