CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows |
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site |
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles |
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed |
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms |
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI |
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description |
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered |
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. |
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. |
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. |
In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible. |
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. |
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. |
In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete. |
In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete. |
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. |
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. |
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. |