Vulnerabilities > Jetbrains > Youtrack > 2022.2.51836

DATE CVE VULNERABILITY TITLE RISK
2025-01-21 CVE-2025-24457 Information Exposure Through Log Files vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
local
low complexity
jetbrains CWE-532
5.5
2025-01-21 CVE-2025-24458 Authentication Bypass by Spoofing vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
local
low complexity
jetbrains CWE-290
7.8
2024-12-04 CVE-2024-54153 Missing Authentication for Critical Function vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
network
low complexity
jetbrains CWE-306
6.5
2024-12-04 CVE-2024-54154 Path Traversal vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
network
low complexity
jetbrains CWE-22
critical
9.8
2024-12-04 CVE-2024-54155 Missing Authentication for Critical Function vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
network
low complexity
jetbrains CWE-306
5.3
2024-12-04 CVE-2024-54156 Unspecified vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
network
low complexity
jetbrains
6.5
2024-12-04 CVE-2024-54157 Unspecified vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
network
low complexity
jetbrains
6.5
2024-12-04 CVE-2024-54158 Authentication Bypass by Spoofing vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
network
low complexity
jetbrains CWE-290
5.3
2024-05-16 CVE-2024-35299 Improper Certificate Validation vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
network
low complexity
jetbrains CWE-295
7.5
2024-03-07 CVE-2024-28228 Authentication Bypass by Spoofing vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
network
low complexity
jetbrains CWE-290
5.3