Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2023-38063MEDIUMIn JetBrains TeamCity before 2023.05.1 stored XSS while running custom builds was possibleEPSS 1.0%CVE-2023-38065MEDIUMIn JetBrains TeamCity before 2023.05.1 stored XSS while viewing the build log was possibleEPSS 1.0%CVE-2023-34221MEDIUMIn JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possibleEPSS 1.0%CVE-2025-46432MEDIUMIn JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logsEPSS 1.0%CVE-2025-31139MEDIUMIn JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build logEPSS 1.0%CVE-2022-48427MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possibleEPSS 1.0%CVE-2022-48426MEDIUMIn JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possibleEPSS 1.0%CVE-2023-35054MEDIUMIn JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possibleEPSS 1.0%CVE-2026-25846MEDIUMIn JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logsEPSS 0.9%CVE-2025-52875MEDIUMIn JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possibleEPSS 0.9%CVE-2026-75047MEDIUMIn JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpointEPSS 0.9%CVE-2022-29930HIGHSHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.EPSS 0.9%CVE-2025-59457HIGHIn JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on WindowsEPSS 0.8%CVE-2025-57734MEDIUMIn JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script filesEPSS 0.8%CVE-2025-67742LOWIn JetBrains TeamCity before 2025.11 path traversal was possible via file uploadEPSS 0.8%CVE-2025-54534MEDIUMIn JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset pageEPSS 0.8%CVE-2026-75050HIGHIn JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parametersEPSS 0.8%CVE-2024-56352MEDIUMIn JetBrains TeamCity before 2024.12 stored XSS was possible via image name on the agent details pageEPSS 0.8%CVE-2024-56355MEDIUMIn JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSSEPSS 0.8%CVE-2022-48476HIGHIn JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible EPSS 0.8%