Loading HuntDB...

Version 0

SINGLE_NUMBER 32 CVEs

Known Vulnerabilities

CVE-2024-54158

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

LOW CVSS 3.5 Published Dec 04, 2024

CVE-2024-54157

In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

MEDIUM CVSS 4.3 Published Dec 04, 2024

CVE-2024-54156

In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

MEDIUM CVSS 4.2 Published Dec 04, 2024

CVE-2024-54155

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

LOW CVSS 3.7 Published Dec 04, 2024

CVE-2024-54154

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

HIGH CVSS 8.0 Published Dec 04, 2024

CVE-2024-54153

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

LOW CVSS 3.1 Published Dec 04, 2024

CVE-2024-50582

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50581

In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50580

In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50579

In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50578

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50577

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50576

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50575

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

MEDIUM CVSS 4.6 Published Oct 28, 2024

CVE-2024-50574

In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

MEDIUM CVSS 5.3 Published Oct 28, 2024

CVE-2024-49579

In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

HIGH CVSS 8.1 Published Oct 17, 2024

CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

MEDIUM CVSS 5.4 Published Oct 10, 2024

CVE-2024-47162

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

MEDIUM CVSS 4.1 Published Sep 19, 2024

CVE-2024-47160

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

MEDIUM CVSS 4.3 Published Sep 19, 2024

CVE-2024-47159

In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

MEDIUM CVSS 4.3 Published Sep 19, 2024

CVE-2024-38506

In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows

MEDIUM CVSS 6.3 Published Jun 18, 2024

CVE-2024-38505

In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

MEDIUM CVSS 5.3 Published Jun 18, 2024

CVE-2024-38504

In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles

MEDIUM CVSS 4.3 Published Jun 18, 2024

CVE-2024-35299

In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

MEDIUM CVSS 5.9 Published May 16, 2024

CVE-2024-28230

In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

MEDIUM CVSS 6.5 Published Mar 07, 2024

CVE-2024-28229

In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

MEDIUM CVSS 6.5 Published Mar 07, 2024

CVE-2024-28228

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

MEDIUM CVSS 5.3 Published Mar 07, 2024

CVE-2024-22370

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

MEDIUM CVSS 4.6 Published Jan 09, 2024

CVE-2023-50871

In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed

MEDIUM CVSS 4.3 Published Dec 15, 2023

CVE-2023-38068

In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms

MEDIUM CVSS 6.5 Published Jul 12, 2023

CVE-2023-35054

In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible

MEDIUM CVSS 4.6 Published Jun 12, 2023

CVE-2023-35053

In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms

HIGH CVSS 7.5 Published Jun 12, 2023