Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-49380LOWIn JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possibleEPSS 0.2%CVE-2026-86486LOWIn JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blankEPSS 0.2%CVE-2025-67739LOWIn JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosureEPSS 0.2%CVE-2026-86496MEDIUMIn JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addressesEPSS 0.2%CVE-2026-86499MEDIUMIn JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permissionEPSS 0.2%CVE-2025-54528MEDIUMIn JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flowEPSS 0.2%CVE-2026-28194MEDIUMIn JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flowEPSS 0.2%CVE-2025-54536MEDIUMIn JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpointEPSS 0.2%CVE-2026-86500MEDIUMIn JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project AdmEPSS 0.2%CVE-2026-28195MEDIUMIn JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurationsEPSS 0.2%CVE-2025-64682LOWIn JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limitEPSS 0.2%CVE-2022-48432MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.EPSS 0.2%CVE-2024-43114HIGHIn JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissionsEPSS 0.2%CVE-2026-75056HIGHIn JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possibleEPSS 0.2%CVE-2025-43013MEDIUMIn JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possibleEPSS 0.2%CVE-2022-29818LOWIn JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawedEPSS 0.1%CVE-2026-64810MEDIUMIn JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity trackingEPSS 0.1%CVE-2026-75060HIGHIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP toolsEPSS 0.1%CVE-2026-86502HIGHIn JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote DeEPSS 0.1%CVE-2026-86491LOWIn JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploadsEPSS 0.1%