|
210031
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
|
CWE-269
Improper Privilege Management
|
CVE-2020-15826
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210032
|
8.8 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
|
NVD-CWE-noinfo
|
CVE-2020-15825
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210033
|
8.8 |
HIGH
Network
|
jetbrains oracle
|
kotlin communications_cloud_native_core_policy banking_extensibility_workbench
|
In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cac…
|
CWE-269
Improper Privilege Management
|
CVE-2020-15824
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210034
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15823
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210035
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15821
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210036
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
|
NVD-CWE-noinfo
|
CVE-2020-15820
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210037
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15819
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210038
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
|
NVD-CWE-noinfo
|
CVE-2020-15818
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210039
|
8.8 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
|
NVD-CWE-noinfo
|
CVE-2020-15817
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210040
|
9.8 |
CRITICAL
Network
|
robotemi
|
robox_os
|
Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it auto…
|
CWE-287
Improper Authentication
|
CVE-2020-16169
|
2024-11-21 14:06 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|