|
222441
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15042
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222442
|
6.1 |
MEDIUM
Network
|
jetbrains
|
upsource
|
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14961
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222443
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
|
NVD-CWE-noinfo
|
CVE-2019-15038
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222444
|
7.8 |
HIGH
Local
|
jetbrains
|
rider
|
JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
|
CWE-426
Untrusted Search Path
|
CVE-2019-14960
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222445
|
5.3 |
MEDIUM
Network
|
jetbrains
|
vim
|
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2019-14957
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222446
|
5.3 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-14955
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222447
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14953
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222448
|
9.8 |
CRITICAL
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
|
CWE-22
Path Traversal
|
CVE-2019-15039
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222449
|
5.9 |
MEDIUM
Network
|
jetbrains
|
intellij_idea
|
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14954
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222450
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14952
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|