Security Vulnerabilities
- CVEs Published In May 2021
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-only mode.
In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.