Vulnerabilidades en JetBrains

332 resultados
Análisis Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-49378MEDIUMIn JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletionEPSS 0.2%CVE-2023-34339LOWIn JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's messageEPSS 0.2%CVE-2022-47895MEDIUMIn JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.EPSS 0.2%CVE-2022-29813MEDIUMIn JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possibleEPSS 0.2%CVE-2026-49376MEDIUMIn JetBrains TeamCity before 2026.1 insufficient username validation in the SAML pluginEPSS 0.2%CVE-2022-29815MEDIUMIn JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possibleEPSS 0.2%CVE-2022-48481MEDIUMIn JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possibleEPSS 0.2%CVE-2025-43015HIGHIn JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfacesEPSS 0.2%CVE-2026-49381LOWIn JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possibleEPSS 0.2%CVE-2025-58335MEDIUMIn JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28EPSS 0.2%CVE-2025-68164LOWIn JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection testEPSS 0.2%CVE-2026-25847HIGHIn JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possibleEPSS 0.2%CVE-2025-64685HIGHIn JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosureEPSS 0.2%CVE-2026-49368HIGHIn JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possibleEPSS 0.2%CVE-2026-49369MEDIUMIn JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pagesEPSS 0.2%CVE-2026-53914MEDIUMIn JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadataEPSS 0.2%CVE-2025-64773LOWIn JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limitEPSS 0.2%CVE-2022-46827LOWIn JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.EPSS 0.2%CVE-2025-67740LOWIn JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadataEPSS 0.2%CVE-2022-37396MEDIUMIn JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code executionEPSS 0.2%