Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2024-24938MEDIUMIn JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentationEPSS 0.7%CVE-2024-54154HIGHIn JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandboxEPSS 0.7%CVE-2022-38180MEDIUMIn JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some casesEPSS 0.7%CVE-2025-47852MEDIUMIn JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possibleEPSS 0.7%CVE-2025-47853MEDIUMIn JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possibleEPSS 0.7%CVE-2026-49377MEDIUMIn JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parametersEPSS 0.7%CVE-2026-61492LOWIn JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possibleEPSS 0.7%CVE-2022-36322MEDIUMIn JetBrains TeamCity before 2022.04.2 build parameter injection was possibleEPSS 0.6%CVE-2022-48433MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.EPSS 0.6%CVE-2025-43012HIGHIn JetBrains Toolbox App before 2.6 command injection in SSH plugin was possibleEPSS 0.6%CVE-2024-50574MEDIUMIn JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionalityEPSS 0.6%CVE-2022-28650HIGHIn JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UIEPSS 0.6%CVE-2026-56142CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaEPSS 0.6%CVE-2022-29035LOWIn JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementationsEPSS 0.6%CVE-2023-35053HIGHIn JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk formsEPSS 0.6%CVE-2015-1313JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request daEPSS 0.6%CVE-2026-50242CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via diEPSS 0.6%CVE-2026-59792CRITICALIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possibleEPSS 0.6%CVE-2022-48429MEDIUMIn JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible EPSS 0.6%CVE-2025-24457MEDIUMIn JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logsEPSS 0.6%