Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2024-54157MEDIUMIn JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detectorEPSS 0.6%CVE-2023-45612HIGHIn JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXEEPSS 0.6%CVE-2022-34894LOWIn JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted servicesEPSS 0.6%CVE-2023-34218CRITICALIn JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possibleEPSS 0.6%CVE-2022-44624MEDIUMIn JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special charactersEPSS 0.6%CVE-2022-44623MEDIUMIn JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settingsEPSS 0.6%CVE-2026-86492HIGHIn JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokensEPSS 0.6%CVE-2022-45471LOWIn JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email addressEPSS 0.6%CVE-2023-38068MEDIUMIn JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk formsEPSS 0.5%CVE-2025-46433MEDIUMIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.5%CVE-2024-31136HIGHIn JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameterEPSS 0.5%CVE-2026-65906HIGHIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.5%CVE-2024-47948MEDIUMIn JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backupsEPSS 0.5%CVE-2024-28173MEDIUMIn JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosedEPSS 0.5%CVE-2023-34227MEDIUMIn JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacksEPSS 0.5%CVE-2026-56141CRITICALIn JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictEPSS 0.5%CVE-2024-28229MEDIUMIn JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articlesEPSS 0.5%CVE-2024-28230MEDIUMIn JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissionsEPSS 0.5%CVE-2026-64813CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development sessionEPSS 0.5%CVE-2024-36362MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was posEPSS 0.5%