Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2025-24461MEDIUMIn JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpointEPSS 0.3%CVE-2024-43807MEDIUMIn JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds pageEPSS 0.3%CVE-2024-56353MEDIUMIn JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookiesEPSS 0.3%CVE-2024-47161MEDIUMIn JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST APIEPSS 0.3%CVE-2024-50577MEDIUMIn JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settingsEPSS 0.3%CVE-2024-24936MEDIUMIn JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missedEPSS 0.3%CVE-2024-50579MEDIUMIn JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possibleEPSS 0.3%CVE-2024-50578MEDIUMIn JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards pageEPSS 0.3%CVE-2024-50582MEDIUMIn JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elementsEPSS 0.3%CVE-2024-50576MEDIUMIn JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifestEPSS 0.3%CVE-2024-50581MEDIUMIn JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tagEPSS 0.3%CVE-2024-50580MEDIUMIn JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering ruleEPSS 0.3%CVE-2024-56354MEDIUMIn JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permissionEPSS 0.3%CVE-2026-57921MEDIUMIn JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpointEPSS 0.3%CVE-2024-56351MEDIUMIn JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user rolesEPSS 0.3%CVE-2026-75045CRITICALIn JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shaEPSS 0.3%CVE-2023-45613MEDIUMIn JetBrains Ktor before 2.3.5 server certificates were not verifiedEPSS 0.3%CVE-2026-49372HIGHIn JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possibleEPSS 0.3%CVE-2026-86497MEDIUMIn JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stEPSS 0.3%CVE-2024-41824MEDIUMIn JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific casesEPSS 0.3%