CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.
In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
