Show filters
100 Total Results
Displaying 11-20 of 100
Sort by:
Attacker Value
Unknown

CVE-2024-50580

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
Attacker Value
Unknown

CVE-2024-50579

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
Attacker Value
Unknown

CVE-2024-50578

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
Attacker Value
Unknown

CVE-2024-50577

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
Attacker Value
Unknown

CVE-2024-50576

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
Attacker Value
Unknown

CVE-2024-50575

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
Attacker Value
Unknown

CVE-2024-50574

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
Attacker Value
Unknown

CVE-2024-49579

Disclosure Date: October 17, 2024 (last updated November 15, 2024)
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
Attacker Value
Unknown

CVE-2024-48902

Disclosure Date: October 10, 2024 (last updated October 17, 2024)
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
Attacker Value
Unknown

CVE-2024-47162

Disclosure Date: September 19, 2024 (last updated September 25, 2024)
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page