Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2025-68164LOWIn JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection testEPSS 0.2%CVE-2026-57922LOWIn JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possibleEPSS 0.2%CVE-2024-38507LOWIn JetBrains Hub before 2024.2.34646 stored XSS via project description was possibleEPSS 0.2%CVE-2024-43808LOWIn JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault pluginEPSS 0.2%CVE-2024-56356MEDIUMIn JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attackEPSS 0.2%CVE-2022-29821MEDIUMIn JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possibleEPSS 0.2%CVE-2024-29880MEDIUMIn JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent processEPSS 0.2%CVE-2026-49374HIGHIn JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parametersEPSS 0.2%CVE-2022-29819MEDIUMIn JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possibleEPSS 0.2%CVE-2022-29814MEDIUMIn JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possibleEPSS 0.2%CVE-2026-86482HIGHIn JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalationEPSS 0.2%CVE-2026-75044HIGHIn JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitEPSS 0.2%CVE-2022-46826MEDIUMIn JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulneraEPSS 0.2%CVE-2026-59791LOWIn JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possibleEPSS 0.2%CVE-2025-43014MEDIUMIn JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmationEPSS 0.2%CVE-2026-49375MEDIUMIn JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download pageEPSS 0.2%CVE-2026-49385MEDIUMIn JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accountsEPSS 0.2%CVE-2022-29815MEDIUMIn JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possibleEPSS 0.2%CVE-2024-50573MEDIUMIn JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized servicesEPSS 0.2%CVE-2025-24458HIGHIn JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integrationEPSS 0.2%