Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-53915HIGHIn JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configurationEPSS 0.5%CVE-2023-50871MEDIUMIn JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missedEPSS 0.4%CVE-2024-38505MEDIUMIn JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party siteEPSS 0.4%CVE-2022-46829HIGHIn JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.EPSS 0.4%CVE-2025-57730MEDIUMIn JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development featureEPSS 0.4%CVE-2026-25848CRITICALIn JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possibleEPSS 0.4%CVE-2022-38133LOWIn JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some casesEPSS 0.4%CVE-2025-32054LOWIn JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log fileEPSS 0.4%CVE-2024-31134MEDIUMIn JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registratioEPSS 0.4%CVE-2026-33392HIGHIn JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypassEPSS 0.4%CVE-2024-31140MEDIUMIn JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing toolsEPSS 0.4%CVE-2024-49579HIGHIn JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requestsEPSS 0.4%CVE-2024-54155LOWIn JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authenticationEPSS 0.4%CVE-2026-65907CRITICALIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possibleEPSS 0.4%CVE-2025-26492HIGHIn JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resourcesEPSS 0.4%CVE-2025-59455MEDIUMIn JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race conditionEPSS 0.4%CVE-2025-48391HIGHIn JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in APIEPSS 0.4%CVE-2024-24943MEDIUMIn JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG imageEPSS 0.4%CVE-2024-22370MEDIUMIn JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possibleEPSS 0.4%CVE-2024-41827HIGHIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.4%