Show filters
456 Total Results
Displaying 161-170 of 456
Sort by:
Attacker Value
Unknown

CVE-2022-48427

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
Attacker Value
Unknown

CVE-2022-48429

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
Attacker Value
Unknown

CVE-2022-48426

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
Attacker Value
Unknown

CVE-2022-48344

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
Attacker Value
Unknown

CVE-2022-48343

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
Attacker Value
Unknown

CVE-2022-48342

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
Attacker Value
Unknown

CVE-2022-47896

Disclosure Date: December 22, 2022 (last updated February 24, 2025)
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
Attacker Value
Unknown

CVE-2022-47895

Disclosure Date: December 22, 2022 (last updated February 24, 2025)
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
Attacker Value
Unknown

CVE-2022-46831

Disclosure Date: December 08, 2022 (last updated February 24, 2025)
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
Attacker Value
Unknown

CVE-2022-46830

Disclosure Date: December 08, 2022 (last updated February 24, 2025)
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.