Product:

Youtrack

(Jetbrains)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 83
Date Id Summary Products Score Patch Annotated
2021-02-03 CVE-2021-25765 In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. Youtrack 8.8
2021-02-03 CVE-2021-25766 In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. Youtrack 5.3
2021-02-03 CVE-2021-25767 In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. Youtrack 5.3
2021-02-03 CVE-2021-25768 In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. Youtrack 5.3
2021-02-03 CVE-2021-25769 In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. Youtrack 7.5
2021-02-03 CVE-2021-25770 In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. Youtrack 9.8
2021-02-03 CVE-2021-25771 In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. Youtrack 4.3
2021-05-11 CVE-2021-27733 In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. Youtrack 5.4
2021-05-11 CVE-2021-31902 In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. Youtrack 7.5
2021-05-11 CVE-2021-31903 In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS. Youtrack 6.1