Vulnerabilidades em JetBrains

332 resultados
Análise Vexday

Com 325 CVEs catalogadas e 3 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos JetBrains é 2 vezes acima da média geral do catálogo, o que indica risco operacional elevado mesmo com volume absoluto relativamente contido. A CVE mais crítica em exploração ativa, CVE-2024-27199, apresenta EPSS de 0,9999 — valor praticamente máximo, sinalizando altíssima probabilidade de exploração em ambientes reais e exigindo atenção imediata de equipes de resposta. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode facilitar comprometimento de sessões e movimentação lateral em ambientes de desenvolvimento. Os 29 CVEs surgidos nos últimos 90 dias e a presença de 4 com PoC pública reforçam a necessidade de ciclos ágeis de patching para produtos desta família.

CVE-2026-57924MEDIUMIn JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile detailsEPSS 0.2%CVE-2026-49380LOWIn JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possibleEPSS 0.2%CVE-2023-38069LOWIn JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain casesEPSS 0.2%CVE-2025-64681LOWIn JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitationsEPSS 0.2%CVE-2025-68166MEDIUMIn JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tabEPSS 0.2%CVE-2025-42921MEDIUMIn JetBrains Toolbox App before 2.6 host key verification was missing in SSH pluginEPSS 0.2%CVE-2026-57923MEDIUMIn JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settingsEPSS 0.2%CVE-2026-28195MEDIUMIn JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurationsEPSS 0.2%CVE-2022-48432MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.EPSS 0.2%CVE-2025-68163LOWIn JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall pageEPSS 0.2%CVE-2024-43114HIGHIn JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissionsEPSS 0.2%CVE-2025-54536MEDIUMIn JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpointEPSS 0.1%CVE-2025-54528MEDIUMIn JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flowEPSS 0.1%CVE-2022-29818LOWIn JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawedEPSS 0.1%CVE-2026-57922LOWIn JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possibleEPSS 0.1%CVE-2025-67739LOWIn JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosureEPSS 0.1%CVE-2025-64682LOWIn JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limitEPSS 0.1%CVE-2026-49382MEDIUMIn JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright pluginEPSS 0.1%CVE-2025-43013MEDIUMIn JetBrains Toolbox App before 2.6 unencrypted credential transmission during SSH authentication was possibleEPSS 0.1%CVE-2025-23385HIGHIn JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 202EPSS 0.1%