Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Filtered by product Youtrack
Total 68 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7913 1 Jetbrains 1 Youtrack 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.
CVE-2019-16171 1 Jetbrains 1 Youtrack 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
CVE-2019-15041 1 Jetbrains 1 Youtrack 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
CVE-2019-12852 1 Jetbrains 1 Youtrack 2024-02-04 7.5 HIGH 9.8 CRITICAL
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
CVE-2019-12850 1 Jetbrains 1 Youtrack 2024-02-04 7.5 HIGH 9.8 CRITICAL
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.
CVE-2019-12866 1 Jetbrains 1 Youtrack 2024-02-04 7.5 HIGH 9.8 CRITICAL
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
CVE-2019-12851 1 Jetbrains 1 Youtrack 2024-02-04 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
CVE-2019-12867 1 Jetbrains 1 Youtrack 2024-02-04 7.5 HIGH 9.8 CRITICAL
Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.