This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Jetbrains First view 2019-07-03
Product Youtrack Last view 2024-01-09
Version 2018.2.42133 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:jetbrains:youtrack

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
5.4 2024-01-09 CVE-2024-22370

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

4.3 2023-12-15 CVE-2023-50871

In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

7.3 2023-07-12 CVE-2023-38068

In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

5.4 2023-06-12 CVE-2023-35054

In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible

7.5 2023-06-12 CVE-2023-35053

In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms

5.4 2022-04-05 CVE-2022-28650

In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI

5.4 2022-04-05 CVE-2022-28649

In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description

5.4 2022-04-05 CVE-2022-28648

In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered

9.8 2022-02-25 CVE-2022-24442

JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

5.4 2022-02-25 CVE-2022-24347

JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.

5.4 2022-02-25 CVE-2022-24344

JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.

4.3 2022-02-25 CVE-2022-24343

In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.

5.4 2021-11-09 CVE-2021-43186

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

9.8 2021-11-09 CVE-2021-43185

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

5.4 2021-11-09 CVE-2021-43184

In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.

4.3 2021-08-06 CVE-2021-37554

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

7.5 2021-08-06 CVE-2021-37553

In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.

5.4 2021-08-06 CVE-2021-37552

In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.

5.3 2021-08-06 CVE-2021-37551

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

7.5 2021-08-06 CVE-2021-37550

In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.

9.1 2021-08-06 CVE-2021-37549

In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.

7.5 2021-05-11 CVE-2021-31905

In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.

6.1 2021-05-11 CVE-2021-31903

In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.

7.5 2021-05-11 CVE-2021-31902

In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

5.4 2021-05-11 CVE-2021-27733

In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.

CWE : Common Weakness Enumeration

%idName
42% (15) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
14% (5) CWE-276 Incorrect Default Permissions
8% (3) CWE-352 Cross-Site Request Forgery (CSRF)
5% (2) CWE-94 Failure to Control Generation of Code ('Code Injection')
2% (1) CWE-799 Improper Control of Interaction Frequency
2% (1) CWE-732 Incorrect Permission Assignment for Critical Resource
2% (1) CWE-697 Insufficient Comparison
2% (1) CWE-668 Exposure of Resource to Wrong Sphere
2% (1) CWE-639 Access Control Bypass Through User-Controlled Key
2% (1) CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
2% (1) CWE-338 Use of Cryptographically Weak PRNG
2% (1) CWE-281 Improper Preservation of Permissions
2% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...
2% (1) CWE-74 Failure to Sanitize Data into a Different Plane ('Injection')