Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jetbrains Subscribe
Filtered by product Youtrack
Total 58 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37551 1 Jetbrains 1 Youtrack 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
CVE-2021-25768 1 Jetbrains 1 Youtrack 2022-07-12 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
CVE-2020-24618 1 Jetbrains 1 Youtrack 2022-04-28 4.0 MEDIUM 6.5 MEDIUM
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
CVE-2022-28649 1 Jetbrains 1 Youtrack 2022-04-18 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
CVE-2022-28648 1 Jetbrains 1 Youtrack 2022-04-18 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
CVE-2022-28650 1 Jetbrains 1 Youtrack 2022-04-18 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
CVE-2022-24442 1 Jetbrains 1 Youtrack 2022-03-03 7.5 HIGH 9.8 CRITICAL
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2022-24347 1 Jetbrains 1 Youtrack 2022-03-03 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
CVE-2022-24344 1 Jetbrains 1 Youtrack 2022-03-03 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
CVE-2022-24343 1 Jetbrains 1 Youtrack 2022-03-03 4.0 MEDIUM 4.3 MEDIUM
In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
CVE-2021-43185 1 Jetbrains 1 Youtrack 2021-11-12 7.5 HIGH 9.8 CRITICAL
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
CVE-2021-43184 1 Jetbrains 1 Youtrack 2021-11-12 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
CVE-2021-43186 1 Jetbrains 1 Youtrack 2021-11-09 3.5 LOW 5.4 MEDIUM
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
CVE-2021-37553 1 Jetbrains 1 Youtrack 2021-08-13 5.0 MEDIUM 7.5 HIGH
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
CVE-2021-37554 1 Jetbrains 1 Youtrack 2021-08-12 4.0 MEDIUM 4.3 MEDIUM
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
CVE-2021-37552 1 Jetbrains 1 Youtrack 2021-08-12 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
CVE-2021-37550 1 Jetbrains 1 Youtrack 2021-08-12 5.0 MEDIUM 7.5 HIGH
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
CVE-2021-37549 1 Jetbrains 1 Youtrack 2021-08-12 6.4 MEDIUM 9.1 CRITICAL
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
CVE-2020-15818 1 Jetbrains 1 Youtrack 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
CVE-2020-11693 1 Jetbrains 1 Youtrack 2021-07-21 5.0 MEDIUM 7.5 HIGH
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.