Product:

Youtrack

(Jetbrains)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 63
Date Id Summary Products Score Patch Annotated
2024-01-09 CVE-2024-22370 In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible Youtrack 5.4
2023-12-15 CVE-2023-50871 In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed Youtrack 4.3
2022-02-25 CVE-2022-24442 JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. Youtrack 9.8
2023-07-12 CVE-2023-38068 In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms Youtrack 7.3
2023-06-12 CVE-2023-35053 In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms Youtrack 7.5
2023-06-12 CVE-2023-35054 In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible Youtrack 5.4
2021-02-03 CVE-2021-25768 In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. Youtrack 5.3
2021-08-06 CVE-2021-37551 In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. Youtrack 5.3
2020-08-27 CVE-2020-24618 In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access. Youtrack 6.5
2022-04-05 CVE-2022-28648 In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered Youtrack 5.4