Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-53914MEDIUMIn JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadataEPSS 0.3%CVE-2026-49367HIGHIn JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user accountEPSS 0.3%CVE-2024-36376MEDIUMIn JetBrains TeamCity before 2024.03.2 users could perform actions that should not be available to them based on their permissionsEPSS 0.3%CVE-2026-64815HIGHIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form filesEPSS 0.3%CVE-2024-36377MEDIUMIn JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissionsEPSS 0.3%CVE-2024-36364MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisherEPSS 0.3%CVE-2022-48430MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 file content could be disclosed via an external stylesheet path in Markdown preview.EPSS 0.3%CVE-2026-62422CRITICALIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass vEPSS 0.3%CVE-2024-43809LOWIn JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset pageEPSS 0.3%CVE-2024-41829LOWIn JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connectionEPSS 0.3%CVE-2025-29904MEDIUMIn JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possibleEPSS 0.3%CVE-2022-28651HIGHIn JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fieldsEPSS 0.3%CVE-2026-59794HIGHIn JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported dataEPSS 0.3%CVE-2026-64814HIGHIn JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development sessionEPSS 0.3%CVE-2023-50870MEDIUMIn JetBrains TeamCity before 2023.11.1 a CSRF on login was possibleEPSS 0.3%CVE-2024-54158LOWIn JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encodingEPSS 0.3%CVE-2024-24941MEDIUMIn JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URLEPSS 0.3%CVE-2022-48342MEDIUMIn JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.EPSS 0.3%CVE-2025-64684MEDIUMIn JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback formEPSS 0.3%CVE-2024-38506MEDIUMIn JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflowsEPSS 0.3%