Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2024-35299MEDIUMIn JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validationEPSS 0.3%CVE-2024-24940LOWIn JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archivesEPSS 0.3%CVE-2026-57925MEDIUMIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tagsEPSS 0.3%CVE-2026-57924MEDIUMIn JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile detailsEPSS 0.3%CVE-2026-86501LOWIn JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.logEPSS 0.3%CVE-2024-35302MEDIUMIn JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possibleEPSS 0.3%CVE-2022-29816LOWIn JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possibleEPSS 0.3%CVE-2025-53959HIGHIn JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possibleEPSS 0.3%CVE-2025-24460MEDIUMIn JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent poolEPSS 0.3%CVE-2024-36367MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via third-party reports was possibleEPSS 0.3%CVE-2024-36372MEDIUMIn JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possibleEPSS 0.3%CVE-2026-44413HIGHIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised accessEPSS 0.3%CVE-2022-40978HIGHThe installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijackingEPSS 0.3%CVE-2024-36370MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was possibleEPSS 0.3%CVE-2024-36369MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was possibleEPSS 0.3%CVE-2024-43810MEDIUMIn JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core pluginEPSS 0.3%CVE-2024-36368MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 reflected XSS via OAuth provider configuration was possibleEPSS 0.3%CVE-2024-41825MEDIUMIn JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tabEPSS 0.3%CVE-2024-36374MEDIUMIn JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possibleEPSS 0.3%CVE-2024-36363MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 several Stored XSS in code inspection reports were possibleEPSS 0.3%