Skip to main content

Vendor/product archive

jetbrains / youtrack CVEs

Beta · best-effort

116 CVEs tagged to jetbrains / youtrack8 Critical, 25 High, 72 Medium, 11 Low, 0 Unrated.

CVE-2024-28230

Published Mar 7, 2024

In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28229

Published Mar 7, 2024

In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28228

Published Mar 7, 2024

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50871

Published Dec 15, 2023

In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38068

Published Jul 12, 2023

In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35054

Published Jun 12, 2023

In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28650

Published Apr 5, 2022

In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28649

Published Apr 5, 2022

In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24442

Published Feb 25, 2022

JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24347

Published Feb 25, 2022

JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24344

Published Feb 25, 2022

JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24343

Published Feb 25, 2022

In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37554

Published Aug 6, 2021

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37551

Published Aug 6, 2021

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37549

Published Aug 6, 2021

In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31905

Published May 11, 2021

In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 116 CVEsPage 3 of 5