Jetbrains
Jetbrains Rider: vulnerabilidades y CVE
Jetbrains Rider tiene 9 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100265 | Media (4.8) | 0.12% | — | 30 sept 2026 | In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation |
| CVE-2025-64457 | Alta (7) | 0.09% | — | 10 nov 2025 | In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition |
| CVE-2025-43016 | Alta (7.5) | 0.37% | — | 25 abr 2025 | In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session |
| CVE-2025-23385 | Alta (7.8) | 0.14% | — | 28 ene 2025 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation… |
| CVE-2024-37051 | Alta (7.5) | 3.8% | — | 10 jun 2024 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4,… |
| CVE-2024-24939 | Media (5.3) | 0.28% | — | 6 feb 2024 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible |
| CVE-2022-37396 | Alta (7.8) | 0.20% | — | 3 ago 2022 | In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution |
| CVE-2020-7906 | Alta (7.5) | 0.67% | — | 30 ene 2020 | In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3. |
| CVE-2019-14960 | Alta (7.8) | 0.34% | — | 1 oct 2019 | JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.