Vulnerabilities > Jetbrains > Youtrack > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-19 | CVE-2024-47160 | Incorrect Authorization vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible | 5.3 |
2024-09-19 | CVE-2024-47162 | Insufficiently Protected Credentials vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page | 5.3 |
2024-06-18 | CVE-2024-38504 | Missing Authorization vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles | 5.3 |
2024-01-09 | CVE-2024-22370 | Cross-site Scripting vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | 5.4 |
2023-12-15 | CVE-2023-50871 | Unspecified vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | 4.3 |
2023-06-12 | CVE-2023-35054 | Cross-site Scripting vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible | 5.4 |
2022-02-25 | CVE-2022-24343 | Incorrect Default Permissions vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. | 4.0 |
2021-08-06 | CVE-2021-37549 | Unspecified vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. | 6.4 |
2021-08-06 | CVE-2021-37550 | Incorrect Comparison vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. | 5.0 |
2021-08-06 | CVE-2021-37551 | Use of Password Hash With Insufficient Computational Effort vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | 5.0 |