Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-41882HIGHIn JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible viEPSS 0.4%CVE-2023-34228MEDIUMIn JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actionsEPSS 0.4%CVE-2023-39173MEDIUMIn JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account accessEPSS 0.4%CVE-2022-28649MEDIUMIn JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue descriptionEPSS 0.4%CVE-2024-46970LOWIn JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possibleEPSS 0.4%CVE-2022-29817LOWIn JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possibleEPSS 0.4%CVE-2022-29820LOWIn JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possibleEPSS 0.4%CVE-2024-36378MEDIUMIn JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokensEPSS 0.4%CVE-2024-31137MEDIUMIn JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configurationEPSS 0.4%CVE-2024-48902MEDIUMIn JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via APEPSS 0.4%CVE-2022-44646LOWIn JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settingsEPSS 0.4%CVE-2022-48344MEDIUMIn JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.EPSS 0.4%CVE-2026-86484MEDIUMIn JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSSEPSS 0.4%CVE-2026-86483MEDIUMIn JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possibleEPSS 0.4%CVE-2025-26493MEDIUMIn JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tabEPSS 0.4%CVE-2024-47160MEDIUMIn JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possibleEPSS 0.4%CVE-2025-43016MEDIUMIn JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug sessionEPSS 0.4%CVE-2025-47850MEDIUMIn JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloningEPSS 0.4%CVE-2023-41250LOWIn JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registrationEPSS 0.4%CVE-2024-38504MEDIUMIn JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articlesEPSS 0.4%