CVEs (116)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality |
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests |
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API |
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page |
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible |
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project |
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows |
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site |
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles |
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation |
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions |
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles |
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible |
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible |
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed |
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms |
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible |
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms |
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI |
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description |