Vulnerabilidades en JetBrains

406 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2023-38064MEDIUMIn JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2023-38067MEDIUMIn JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent logEPSS 0.5%CVE-2025-67741MEDIUMIn JetBrains TeamCity before 2025.11 stored XSS was possible via session attributeEPSS 0.5%CVE-2026-64800LOWIn JetBrains GoLand before 2026.2 sensitive configuration values written to log files by defaultEPSS 0.5%CVE-2026-59793HIGHIn JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integrationEPSS 0.5%CVE-2022-29811MEDIUMIn JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.EPSS 0.5%CVE-2024-31139MEDIUMIn JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detectorEPSS 0.5%CVE-2022-29928MEDIUMIn JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possibleEPSS 0.5%CVE-2024-31135MEDIUMIn JetBrains TeamCity before 2024.03 open redirect was possible on the login pageEPSS 0.5%CVE-2024-28228MEDIUMIn JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possibleEPSS 0.5%CVE-2025-59458HIGHIn JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28EPSS 0.5%CVE-2022-48477MEDIUMIn JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing EPSS 0.5%CVE-2022-46830MEDIUMIn JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.EPSS 0.5%CVE-2026-64812CRITICALIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.5%CVE-2022-38179MEDIUMJetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attackEPSS 0.5%CVE-2022-44622LOWIn JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessiveEPSS 0.5%CVE-2024-36470HIGHIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge casesEPSS 0.5%CVE-2022-29929LOWIn JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possibleEPSS 0.5%CVE-2022-46831MEDIUMIn JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity projectEPSS 0.5%CVE-2026-49366HIGHIn JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completionEPSS 0.5%