CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration | 7.8 |
High |
||
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs | 5.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack | 6.5 |
Medium |
||
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication | 5.3 |
Medium |
||
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | 9.8 |
Critical |
||
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter | 6.5 |
Medium |