Vulnerabilities
Vulnerable Software
Security Vulnerabilities
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
CVSS Score
7.7
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVSS Score
5.9
EPSS Score
0.003
Published
2026-09-30
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
CVSS Score
8.1
EPSS Score
0.004
Published
2026-09-30
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
CVSS Score
4.3
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
CVSS Score
4.3
EPSS Score
0.007
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
CVSS Score
4.3
EPSS Score
0.002
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
CVSS Score
5.3
EPSS Score
0.003
Published
2026-09-30
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVSS Score
5.4
EPSS Score
0.002
Published
2026-09-30
Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
CVSS Score
4.8
EPSS Score
0.005
Published
2026-09-30


Contact Us

Shodan ® - All rights reserved