Vulnerabilidades en JetBrains

359 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2024-27199HIGHIn JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possibleEPSS 100.0%KEVCVE-2023-42793CRITICALIn JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possibleEPSS 100.0%KEVCVE-2024-27198CRITICALIn JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possibleEPSS 99.9%KEVCVE-2024-31138MEDIUMIn JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settingsEPSS 74.5%CVE-2022-48428MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possibleEPSS 68.0%CVE-2023-34220MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in the Commit Status Publisher window was possibleEPSS 61.2%CVE-2023-34225MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possibleEPSS 60.7%CVE-2022-48343MEDIUMIn JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.EPSS 59.5%CVE-2025-46618LOWIn JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tabEPSS 59.0%CVE-2024-23917CRITICALIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possibleEPSS 53.7%CVE-2023-41249MEDIUMIn JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build StepEPSS 53.1%CVE-2024-24942MEDIUMIn JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archivesEPSS 32.0%CVE-2025-31140MEDIUMIn JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles pageEPSS 27.2%CVE-2024-47949MEDIUMIn JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary locationEPSS 23.5%CVE-2025-52876MEDIUMIn JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possibleEPSS 17.1%CVE-2025-52877MEDIUMIn JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possibleEPSS 16.7%CVE-2026-49373HIGHIn JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settingsEPSS 13.0%CVE-2025-59456MEDIUMIn JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive uploadEPSS 12.2%CVE-2024-37051CRITICALGitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023EPSS 3.8%CVE-2025-68165MEDIUMIn JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setupEPSS 3.7%