Skip to main content

Vendor/product archive

jetbrains / youtrack CVEs

Beta · best-effort

116 CVEs tagged to jetbrains / youtrack8 Critical, 25 High, 72 Medium, 11 Low, 0 Unrated.

CVE-2021-31903

Published May 11, 2021

In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31902

Published May 11, 2021

In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27733

Published May 11, 2021

In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25771

Published Feb 3, 2021

In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25770

Published Feb 3, 2021

In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25769

Published Feb 3, 2021

In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25768

Published Feb 3, 2021

In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25767

Published Feb 3, 2021

In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25766

Published Feb 3, 2021

In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25208

Published Feb 3, 2021

In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27625

Published Nov 16, 2020

In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25210

Published Nov 16, 2020

In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25209

Published Nov 16, 2020

In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24366

Published Nov 16, 2020

Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-15822

Published Oct 19, 2020

In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24618

Published Aug 27, 2020

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15821

Published Aug 8, 2020

In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15820

Published Aug 8, 2020

In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15819

Published Aug 8, 2020

JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15818

Published Aug 8, 2020

In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15817

Published Aug 8, 2020

In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 116 CVEsPage 4 of 5