Skip to main content

Vendor/product archive

jetbrains / rider CVEs

Beta · best-effort

8 CVEs tagged to jetbrains / rider1 Critical, 3 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2025-43016

Published Apr 25, 2025

In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37051

Published Jun 10, 2024

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2024-24939

Published Feb 6, 2024

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-37396

Published Aug 3, 2022

In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7906

Published Jan 30, 2020

In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14960

Published Oct 1, 2019

JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1