Security Vulnerabilities
- CVEs Published In August 2020
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
In JetBrains ToolBox version 1.17 before 1.17.6856, the set of signature verifications omitted the jetbrains-toolbox.exe file.
In JetBrains TeamCity before 2020.1.1, project parameter values can be retrieved by a user without appropriate permissions.
In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.