JetBrains kayıtları
jetbrains üreticisine ait 658 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %0,6
- Silahlaştırılmış
- 4 · %0,6
- Pre-auth RCE
- 26
- Düzeltme kaydı olan
- %59,1
- Yayından KEV’e ortanca
- 12 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')131
- CWE-862 Missing Authorization36
- CWE-863 Incorrect Authorization29
- CWE-532 Insertion of Sensitive Information into Log File19
- CWE-918 Server-Side Request Forgery (SSRF)18
- CWE-94 Improper Control of Generation of Code ('Code Injection')16
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
658 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2023-42793Silahlaştırılmış | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possiblejetbrains · teamcity · CWE-288 | Kritik9,8 | KEV | %100,0 | 19 Eyl 2023 |
99Hemen | CVE-2024-27198Silahlaştırılmış | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possiblejetbrains · teamcity · CWE-288 | Kritik9,8 | KEV | %99,9 | 4 Mar 2024 |
96Hemen | CVE-2026-63077Silahlaştırılmış | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocoljetbrains · teamcity · CWE-502 | Kritik9,8 | KEV | %89,6 | 27 Tem 2026 |
89Hemen | CVE-2024-27199Silahlaştırılmış | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possiblejetbrains · teamcity · CWE-23 | Yüksek7,3 | KEV | %100,0 | 4 Mar 2024 |
55Planlayın | CVE-2024-23917Kavram kanıtı | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possiblejetbrains · teamcity · CWE-288 | Kritik9,8 | — | %54,0 | 6 Şub 2024 |
43Planlayın | CVE-2024-31138İstismar yok | In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settingsjetbrains · teamcity · CWE-79 | Orta5,4 | — | %74,5 | 28 Mar 2024 |
43Planlayın | CVE-2025-46618İstismar yok | In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tabjetbrains · teamcity · CWE-79 | Orta6,1 | — | %63,0 | 25 Nis 2025 |
43Planlayın | CVE-2019-15039Kavram kanıtı | An issue was discovered in JetBrains TeamCity 2018.2.4.jetbrains · teamcity · CWE-22 | Kritik9,8 | — | %12,9 | 1 Eki 2019 |
42Planlayın | CVE-2022-48343İstismar yok | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.jetbrains · teamcity · CWE-79 | Orta6,1 | — | %59,5 | 23 Şub 2023 |
41Planlayın | CVE-2022-48428İstismar yok | In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possiblejetbrains · teamcity · CWE-79 | Orta5,4 | — | %68,0 | 27 Mar 2023 |
41Planlayın | CVE-2023-41249İstismar yok | In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Stepjetbrains · teamcity · CWE-79 | Orta6,1 | — | %55,5 | 25 Ağu 2023 |
40Planlayın | CVE-2020-25207İstismar yok | JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.jetbrains · toolbox | Kritik9,8 | — | %4,6 | 16 Kas 2020 |
40Planlayın | CVE-2019-9186İstismar yok | In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute cojetbrains · intellij idea · CWE-668 | Kritik9,8 | — | %4,5 | 3 Tem 2019 |
40Planlayın | CVE-2019-10104İstismar yok | In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with jetbrains · intellij idea | Kritik9,8 | — | %3,8 | 3 Tem 2019 |
40Planlayın | CVE-2022-24442Kavram kanıtı | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.jetbrains · youtrack · CWE-94 | Kritik9,8 | — | %3,8 | 25 Şub 2022 |
40Planlayın | CVE-2019-18364İstismar yok | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.jetbrains · teamcity · CWE-502 | Kritik9,8 | — | %3,5 | 31 Eki 2019 |
40Planlayın | CVE-2021-25770İstismar yok | In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.jetbrains · youtrack · CWE-94 | Kritik9,8 | — | %3,5 | 3 Şub 2021 |
40Planlayın | CVE-2021-31915İstismar yok | In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.jetbrains · teamcity · CWE-78 | Kritik9,8 | — | %3,2 | 11 May 2021 |
40Planlayın | CVE-2021-31909İstismar yok | In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.jetbrains · teamcity · CWE-88 | Kritik9,8 | — | %3,2 | 11 May 2021 |
40Planlayın | CVE-2020-11690İstismar yok | In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.jetbrains · intellij idea | Kritik9,8 | — | %2,3 | 22 Nis 2020 |
40Planlayın | CVE-2021-31914İstismar yok | In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.jetbrains · teamcity | Kritik9,8 | — | %2,3 | 11 May 2021 |
40Planlayın | CVE-2019-10100İstismar yok | In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection.jetbrains · youtrack integration · CWE-94 | Kritik9,8 | — | %2,2 | 3 Tem 2019 |
40Planlayın | CVE-2019-12736İstismar yok | JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injecjetbrains · ktor · CWE-77 | Kritik9,8 | — | %2,2 | 2 Eki 2019 |
40Planlayın | CVE-2019-12850İstismar yok | A query injection was possible in JetBrains YouTrack.jetbrains · youtrack · CWE-89 | Kritik9,8 | — | %2,1 | 3 Tem 2019 |
40Planlayın | CVE-2022-25263İstismar yok | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.jetbrains · teamcity · CWE-78 | Kritik9,8 | — | %2,0 | 25 Şub 2022 |
- CVE-2023-4279399Hemen
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100jetbrains · teamcity19 Eyl 2023
- CVE-2024-2719899Hemen
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100jetbrains · teamcity4 Mar 2024
- CVE-2026-6307796Hemen
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90jetbrains · teamcity27 Tem 2026
- CVE-2024-2719989Hemen
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %100jetbrains · teamcity4 Mar 2024
- CVE-2024-2391755Planlayın
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
KritikCVSS 9,8Kavram kanıtıEPSS %54jetbrains · teamcity6 Şub 2024
- CVE-2024-3113843Planlayın
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings
OrtaCVSS 5,4İstismar yokEPSS %75jetbrains · teamcity28 Mar 2024
- CVE-2025-4661843Planlayın
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
OrtaCVSS 6,1İstismar yokEPSS %63jetbrains · teamcity25 Nis 2025
- CVE-2019-1503943Planlayın
An issue was discovered in JetBrains TeamCity 2018.2.4.
KritikCVSS 9,8Kavram kanıtıEPSS %13jetbrains · teamcity1 Eki 2019
- CVE-2022-4834342Planlayın
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
OrtaCVSS 6,1İstismar yokEPSS %59jetbrains · teamcity23 Şub 2023
- CVE-2022-4842841Planlayın
In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
OrtaCVSS 5,4İstismar yokEPSS %68jetbrains · teamcity27 Mar 2023
- CVE-2023-4124941Planlayın
In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step
OrtaCVSS 6,1İstismar yokEPSS %56jetbrains · teamcity25 Ağu 2023
- CVE-2020-2520740Planlayın
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
KritikCVSS 9,8İstismar yokEPSS %5jetbrains · toolbox16 Kas 2020
- CVE-2019-918640Planlayın
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute co
KritikCVSS 9,8İstismar yokEPSS %5jetbrains · intellij idea3 Tem 2019
- CVE-2019-1010440Planlayın
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with
KritikCVSS 9,8İstismar yokEPSS %4jetbrains · intellij idea3 Tem 2019
- CVE-2022-2444240Planlayın
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
KritikCVSS 9,8Kavram kanıtıEPSS %4jetbrains · youtrack25 Şub 2022
- CVE-2019-1836440Planlayın
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
KritikCVSS 9,8İstismar yokEPSS %3jetbrains · teamcity31 Eki 2019
- CVE-2021-2577040Planlayın
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
KritikCVSS 9,8İstismar yokEPSS %3jetbrains · youtrack3 Şub 2021
- CVE-2021-3191540Planlayın
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
KritikCVSS 9,8İstismar yokEPSS %3jetbrains · teamcity11 May 2021
- CVE-2021-3190940Planlayın
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
KritikCVSS 9,8İstismar yokEPSS %3jetbrains · teamcity11 May 2021
- CVE-2020-1169040Planlayın
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · intellij idea22 Nis 2020
- CVE-2021-3191440Planlayın
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · teamcity11 May 2021
- CVE-2019-1010040Planlayın
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection.
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · youtrack integration3 Tem 2019
- CVE-2019-1273640Planlayın
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injec
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · ktor2 Eki 2019
- CVE-2019-1285040Planlayın
A query injection was possible in JetBrains YouTrack.
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · youtrack3 Tem 2019
- CVE-2022-2526340Planlayın
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
KritikCVSS 9,8İstismar yokEPSS %2jetbrains · teamcity25 Şub 2022