Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2024-41826LOWIn JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection pageEPSS 0.3%CVE-2024-35300LOWIn JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possibleEPSS 0.3%CVE-2026-86480CRITICALIn JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privilegesEPSS 0.3%CVE-2024-39879MEDIUMIn JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settingsEPSS 0.3%CVE-2025-54531HIGHIn JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on WindowsEPSS 0.3%CVE-2025-24456MEDIUMIn JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mappingEPSS 0.3%CVE-2026-68762MEDIUMIn JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possibleEPSS 0.3%CVE-2025-58334HIGHIn JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for tEPSS 0.3%CVE-2024-24939LOWIn JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possibleEPSS 0.3%CVE-2025-57731HIGHIn JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram contentEPSS 0.3%CVE-2024-41828LOWIn JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant timeEPSS 0.3%CVE-2023-39261MEDIUMIn JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissionsEPSS 0.3%CVE-2024-36366MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 an XSS could be executed via certain report grouping and filtering oEPSS 0.3%CVE-2024-36365MEDIUMIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agentEPSS 0.3%CVE-2024-56348MEDIUMIn JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agentsEPSS 0.3%CVE-2024-56350MEDIUMIn JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projectsEPSS 0.3%CVE-2025-57733MEDIUMIn JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email contentEPSS 0.3%CVE-2024-39878MEDIUMIn JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App ConnectionEPSS 0.3%CVE-2024-56349MEDIUMIn JetBrains TeamCity before 2024.12 improper access control allowed unauthorized users to modify build logsEPSS 0.3%CVE-2022-46828MEDIUMIn JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.EPSS 0.3%