CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | 7.8 |
High |
||
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | 5.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | 9.8 |
Critical |
||
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible | 6.1 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API | 6.1 |
Medium |
||
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality | 7.5 |
High |
||
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests | 8.1 |
High |
||
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API | 5.4 |
Medium |
||
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project | 4.3 |
Medium |
||
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows | 8.1 |
High |
||
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site | 7.5 |
High |
||
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation | 7.5 |
High |
||
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible | 5.3 |
Medium |