Youtrack
by Jetbrains
CVEs (123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43191 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS. | ||
| CVE-2021-43190 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible. | ||
| CVE-2021-43187 | Med | 0.35 | 5.3 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information. | ||
| CVE-2021-43186 | Med | 0.35 | 5.4 | 0.01 | Nov 9, 2021 | JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. | ||
| CVE-2021-43184 | Med | 0.35 | 5.4 | 0.01 | Nov 9, 2021 | In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. | ||
| CVE-2021-37552 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. | ||
| CVE-2021-37551 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | ||
| CVE-2021-27733 | Med | 0.35 | 5.4 | 0.01 | May 11, 2021 | In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. | ||
| CVE-2021-25768 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. | ||
| CVE-2021-25767 | Med | 0.35 | 5.3 | 0.03 | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. | ||
| CVE-2021-25766 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. | ||
| CVE-2020-25208 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions. | ||
| CVE-2020-27626 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF. | ||
| CVE-2020-27625 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues. | ||
| CVE-2020-27624 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. | ||
| CVE-2020-25210 | Med | 0.35 | 5.3 | 0.01 | Nov 16, 2020 | In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants. | ||
| CVE-2020-15820 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence. | ||
| CVE-2020-15819 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports. | ||
| CVE-2020-15818 | Med | 0.35 | 5.3 | 0.01 | Aug 8, 2020 | In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence. | ||
| CVE-2020-7912 | Med | 0.35 | 5.3 | 0.01 | Jan 30, 2020 | In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups. |
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
- risk 0.35cvss 5.4epss 0.01
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
- risk 0.35cvss 5.4epss 0.01
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
- risk 0.35cvss 5.3epss 0.03
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
- risk 0.35cvss 5.3epss 0.01
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
- risk 0.35cvss 5.3epss 0.01
In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.
Page 4 of 7