Jetbrains Security Vulnerabilities (CVEs)
Track 147 security vulnerabilities affecting Jetbrains products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability allows local privilege escalation via the ETW Host Service in JetBrains development tools. Attackers with initial access to a syste...
Jan 28, 2025This vulnerability in JetBrains TeamCity allows unauthorized decryption of connection secrets via the Test Connection endpoint. Attackers with access ...
Jan 21, 2025JetBrains YouTrack versions before 2024.3.55417 expose permanent authentication tokens in application logs. This vulnerability allows attackers with a...
Jan 21, 2025This vulnerability in JetBrains YouTrack allows attackers to take over user accounts by spoofing email addresses and exploiting the Helpdesk integrati...
Jan 21, 2025This vulnerability allows reflected cross-site scripting (XSS) attacks on the Vault Connection page in JetBrains TeamCity. Attackers can inject malici...
Jan 21, 2025JetBrains TeamCity backup files exposed user credentials and session cookies in versions before 2024.12. This vulnerability allows attackers with acce...
Dec 20, 2024JetBrains TeamCity versions before 2024.12 have a cross-site scripting (XSS) vulnerability in the RemoteBuildLogController due to missing Content-Type...
Dec 20, 2024This vulnerability in JetBrains TeamCity allows unauthorized users to modify build logs due to improper access control. It affects organizations using...
Dec 20, 2024This vulnerability in JetBrains TeamCity allows access tokens to remain valid after user roles are removed, potentially enabling unauthorized access. ...
Dec 20, 2024This CVE describes a prototype pollution vulnerability in JetBrains YouTrack issue tracking software. Attackers can manipulate JavaScript object proto...
Dec 4, 2024This vulnerability allows attackers to inject malicious scripts into JetBrains YouTrack web pages through specially crafted links. When users click th...
Oct 28, 2024This vulnerability allows attackers to inject malicious scripts into YouTrack comments due to improper HTML sanitization. When exploited, it enables c...
Oct 28, 2024This vulnerability in JetBrains Hub allows authenticated users to generate permanent authentication tokens for services they shouldn't have access to....
Oct 28, 2024This vulnerability allows reflected cross-site scripting (XSS) attacks in JetBrains YouTrack's Widget API. Attackers can inject malicious scripts that...
Oct 28, 2024This stored cross-site scripting (XSS) vulnerability in JetBrains YouTrack allows attackers to inject malicious Angular templates into Hub settings, w...
Oct 28, 2024The CVE-2024-49580 vulnerability in JetBrains Ktor's HttpCache Plugin involves improper caching that could allow unauthorized disclosure of cached HTT...
Oct 17, 2024This vulnerability in JetBrains TeamCity allows passwords to be exposed through the Sonar runner REST API. Attackers could potentially retrieve sensit...
Oct 8, 2024This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to write backup files to arbitrary locations on the serv...
Oct 8, 2024This vulnerability in JetBrains YouTrack allows unauthorized users to access global application configuration data. It affects all YouTrack instances ...
Sep 19, 2024This vulnerability allows attackers to inject malicious scripts into the Clouds page of JetBrains TeamCity, which are then executed when other users v...
Aug 16, 2024This vulnerability allows attackers to inject malicious scripts into web pages viewed by TeamCity users through the AWS Core plugin. When exploited, i...
Aug 16, 2024This vulnerability in JetBrains TeamCity allows attackers to escalate privileges due to incorrect directory permissions. It affects all TeamCity insta...
Aug 6, 2024This vulnerability allows access tokens in JetBrains TeamCity to remain functional after they have been deleted or expired, creating an authentication...
Jul 22, 2024This vulnerability in JetBrains TeamCity allows password-type parameters to leak into build logs under specific conditions. It affects organizations u...
Jul 22, 2024This vulnerability in JetBrains TeamCity exposes application tokens in EC2 Cloud Profile settings, potentially allowing unauthorized access to cloud r...
Jul 1, 2024This vulnerability allows users without proper permissions to enable the auto-attach option for workflows in JetBrains YouTrack. This could lead to un...
Jun 18, 2024This vulnerability allows guest users in JetBrains YouTrack to attach files to articles, which should be restricted. It affects YouTrack instances wit...
Jun 18, 2024This vulnerability in JetBrains IDEs exposes GitHub access tokens to third-party websites, potentially allowing attackers to steal credentials and acc...
Jun 10, 2024This CVE describes an authorization bypass vulnerability in JetBrains TeamCity where users could perform actions beyond their assigned permissions. It...
May 29, 2024JetBrains TeamCity servers before version 2024.03.2 are vulnerable to denial-of-service attacks when receiving malformed authentication tokens. This v...
May 29, 2024This CVE describes an authentication bypass vulnerability in JetBrains TeamCity CI/CD servers. Attackers could potentially gain unauthorized access to...
May 29, 2024This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into OAuth connection settings...
May 29, 2024This vulnerability allows reflected cross-site scripting (XSS) attacks on the subscriptions page of JetBrains TeamCity. Attackers can inject malicious...
May 29, 2024This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into build step settings. When...
May 29, 2024This Cross-Site Scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into web pages viewed by other users....
May 29, 2024This vulnerability allows reflected cross-site scripting (XSS) attacks via OAuth provider configuration in JetBrains TeamCity. Attackers can inject ma...
May 29, 2024This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to read arbitrary files from the server filesystem. The ...
May 29, 2024This vulnerability in JetBrains TeamCity allows improper access control in Pull Requests and Commit status publisher build features. Attackers could p...
May 29, 2024This vulnerability in JetBrains YouTrack allows man-in-the-middle attacks due to improper certificate hostname validation in SMTPS protocol communicat...
May 16, 2024This vulnerability in JetBrains TeamCity allows GitHub App tokens to be used beyond their intended project scope, potentially enabling unauthorized ac...
May 16, 2024This vulnerability allows attackers to bypass two-factor authentication (2FA) in JetBrains TeamCity by using a special URL parameter. It affects all T...
Mar 28, 2024CVE-2024-27198 is an authentication bypass vulnerability in JetBrains TeamCity CI/CD servers that allows unauthenticated attackers to perform administ...
Mar 4, 2024This critical vulnerability in JetBrains TeamCity allows attackers to bypass authentication mechanisms and achieve remote code execution (RCE) on affe...
Feb 6, 2024This vulnerability in JetBrains Ktor's ContentNegotiation feature with XML format allows attackers to perform XML External Entity (XXE) attacks, poten...
Oct 9, 2023CVE-2023-42793 is a critical authentication bypass vulnerability in JetBrains TeamCity CI/CD servers that allows unauthenticated attackers to execute ...
Sep 19, 2023This vulnerability in JetBrains TeamCity allows attackers to bypass permission checks and perform administrative actions without proper authorization....
May 31, 2023This vulnerability allows attackers to obtain NTLM password hashes through the built-in web server API in JetBrains IntelliJ IDEA. It affects users ru...
Mar 29, 2023This vulnerability in JetBrains IntelliJ IDEA allows Gradle and Maven projects to be imported without requiring the 'Trust Project' confirmation dialo...
Mar 29, 2023This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into the SSH keys page. When a...
Mar 27, 2023This stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity allows attackers to inject malicious scripts into Perforce connection setti...
Mar 27, 2023Why Monitor Jetbrains Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 147+ known vulnerabilities affecting Jetbrains products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Jetbrains packages in under 60 seconds. No agents required - completely agentless scanning that works across Jetbrains deployments.
Free vulnerability database: Access detailed information about every Jetbrains CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Jetbrains CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions