Vulnerabilities
Vulnerable Software
Jetbrains:  Security Vulnerabilities
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
CVSS Score
6.2
EPSS Score
0.002
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVSS Score
3.9
EPSS Score
0.002
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVSS Score
5.2
EPSS Score
0.003
Published
2022-12-08
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
CVSS Score
7.1
EPSS Score
0.004
Published
2022-12-08
In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVSS Score
4.1
EPSS Score
0.005
Published
2022-12-08
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
CVSS Score
6.6
EPSS Score
0.005
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
CVSS Score
5.6
EPSS Score
0.002
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
CVSS Score
4.0
EPSS Score
0.001
Published
2022-12-08
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
CVSS Score
3.5
EPSS Score
0.006
Published
2022-11-18
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
CVSS Score
2.2
EPSS Score
0.004
Published
2022-11-03


Contact Us

Shodan ® - All rights reserved