CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
In JetBrains TeamCity before 2020.2.3, XSS was possible.
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
