Medium
CVSS: 5.2
In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible
Medium
CVSS: 4.6
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
High
CVSS: 7.7
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
High
CVSS: 7.8
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Serv…
Medium
CVSS: 6.5
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
Medium
CVSS: 4.3
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Medium
CVSS: 4.6
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
High
CVSS: 7.1
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
Medium
CVSS: 5.5
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
Medium
CVSS: 6.7
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping