Vulnerabilidades em JetBrains

406 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2024-54153LOWIn JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameterEPSS 0.4%CVE-2023-41248MEDIUMIn JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configurationEPSS 0.4%CVE-2024-24937MEDIUMIn JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possibleEPSS 0.4%CVE-2024-50575MEDIUMIn JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget APIEPSS 0.4%CVE-2025-31141LOWIn JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles pageEPSS 0.4%CVE-2022-40979MEDIUMIn JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executableEPSS 0.4%CVE-2026-86478CRITICALIn JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeoEPSS 0.4%CVE-2024-47162MEDIUMIn JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports pageEPSS 0.4%CVE-2023-34219MEDIUMIn JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration seEPSS 0.4%CVE-2024-49580MEDIUMIn JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosureEPSS 0.4%CVE-2026-59796HIGHIn JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checksEPSS 0.4%CVE-2023-34224MEDIUMIn JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possibleEPSS 0.3%CVE-2024-36375MEDIUMIn JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposedEPSS 0.3%CVE-2024-54156MEDIUMIn JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attackEPSS 0.3%CVE-2026-59795HIGHIn JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possibleEPSS 0.3%CVE-2026-57926LOWIn JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attackEPSS 0.3%CVE-2024-28174MEDIUMIn JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperlyEPSS 0.3%CVE-2023-51655MEDIUMIn JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specifiedEPSS 0.3%CVE-2024-47159MEDIUMIn JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a projectEPSS 0.3%CVE-2025-52878MEDIUMIn JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissionsEPSS 0.3%