|
210251
|
2.7 |
LOW
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11692
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210252
|
7.5 |
HIGH
Network
|
jetbrains
|
hub
|
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
|
NVD-CWE-noinfo
|
CVE-2020-11691
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210253
|
9.8 |
CRITICAL
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
|
NVD-CWE-Other
|
CVE-2020-11690
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210254
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11689
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210255
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-11688
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210256
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
|
CWE-200
Information Exposure
|
CVE-2020-11687
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210257
|
2.7 |
LOW
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
|
NVD-CWE-noinfo
|
CVE-2020-11686
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210258
|
7.5 |
HIGH
Network
|
jetbrains
|
goland
|
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-11685
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210259
|
8.1 |
HIGH
Adjacent
|
titan
|
sf_rush_smart_band_firmware
|
An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the a…
|
CWE-347 CWE-306 CWE-319
Improper Verification of Cryptographic Signature Missing Authentication for Critical Function Cleartext Transmission of Sensitive Information
|
CVE-2020-11539
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210260
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups.
|
NVD-CWE-noinfo
|
CVE-2020-11891
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|