JetBrains / Upsource
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-30482 | In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly | HIGH | 7.5 | May 11, 2021 |
| CVE-2019-19704 | In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm. | HIGH | 7.5 | Aug 8, 2020 |
| CVE-2019-12156 | Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2… | MEDIUM | 5.3 | Oct 2, 2019 |
| CVE-2019-12157 | In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. | CRITICAL | 9.8 | Oct 2, 2019 |
| CVE-2019-14961 | JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. | MEDIUM | 6.1 | Oct 1, 2019 |
Showing 1 to 5 of 5 CVEs