Security Vulnerabilities
- CVEs Published In February 2021
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.