|
211101
|
4.9 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
|
NVD-CWE-noinfo
|
CVE-2020-11938
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211102
|
9.8 |
CRITICAL
Network
|
jetbrains
|
space
|
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
|
CWE-287
Improper Authentication
|
CVE-2020-11796
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211103
|
7.5 |
HIGH
Network
|
jetbrains
|
space
|
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-11795
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211104
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
|
NVD-CWE-noinfo
|
CVE-2020-11693
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211105
|
2.7 |
LOW
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11692
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211106
|
7.5 |
HIGH
Network
|
jetbrains
|
hub
|
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
|
NVD-CWE-noinfo
|
CVE-2020-11691
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211107
|
9.8 |
CRITICAL
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.
|
NVD-CWE-Other
|
CVE-2020-11690
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211108
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11689
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211109
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-11688
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211110
|
7.5 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
|
CWE-200
Information Exposure
|
CVE-2020-11687
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|