Vulnerabilities > Jetbrains > Youtrack

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-43185 Injection vulnerability in Jetbrains Youtrack
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
network
low complexity
jetbrains CWE-74
critical
9.8
2021-11-09 CVE-2021-43186 Cross-site Scripting vulnerability in Jetbrains Youtrack
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
network
low complexity
jetbrains CWE-79
5.4
2021-08-06 CVE-2021-37549 Unspecified vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
network
low complexity
jetbrains
critical
9.1
2021-08-06 CVE-2021-37550 Incorrect Comparison vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
network
low complexity
jetbrains CWE-697
7.5
2021-08-06 CVE-2021-37551 Use of Password Hash With Insufficient Computational Effort vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
network
low complexity
jetbrains CWE-916
5.3
2021-08-06 CVE-2021-37552 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
network
low complexity
jetbrains CWE-79
5.4
2021-08-06 CVE-2021-37553 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
network
low complexity
jetbrains CWE-338
7.5
2021-08-06 CVE-2021-37554 Unspecified vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
network
low complexity
jetbrains
4.3
2021-05-11 CVE-2021-27733 Cross-site Scripting vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
network
low complexity
jetbrains CWE-79
5.4
2021-05-11 CVE-2021-31902 Incorrect Permission Assignment for Critical Resource vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
network
low complexity
jetbrains CWE-732
7.5