VYPR

by Jetbrains

CVEs (48)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-244570.000.00Jan 21, 2025In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
CVE-2024-541580.000.00Dec 4, 2024In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
CVE-2024-541570.000.00Dec 4, 2024In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
CVE-2024-541560.000.00Dec 4, 2024In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
CVE-2024-541550.000.00Dec 4, 2024In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
CVE-2024-541540.000.00Dec 4, 2024In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
CVE-2024-541530.000.00Dec 4, 2024In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
CVE-2024-505740.000.00Oct 28, 2024In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
CVE-2024-495790.000.00Oct 17, 2024In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
CVE-2024-489020.000.00Oct 10, 2024In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
CVE-2024-471620.000.00Sep 19, 2024In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
CVE-2024-471600.000.00Sep 19, 2024In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
CVE-2024-471590.000.00Sep 19, 2024In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
CVE-2024-385060.000.00Jun 18, 2024In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
CVE-2024-385050.000.00Jun 18, 2024In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
CVE-2024-385040.000.00Jun 18, 2024In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
CVE-2024-352990.000.00May 16, 2024In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
CVE-2024-282300.000.00Mar 7, 2024In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
CVE-2024-282290.000.00Mar 7, 2024In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
CVE-2024-282280.000.00Mar 7, 2024In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible