Show filters
249 Total Results
Displaying 131-140 of 249
Sort by:
Attacker Value
Unknown

CVE-2021-25767

Disclosure Date: February 03, 2021 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
Attacker Value
Unknown

CVE-2021-25769

Disclosure Date: February 03, 2021 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
Attacker Value
Unknown

CVE-2021-25768

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
Attacker Value
Unknown

CVE-2021-25765

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
Attacker Value
Unknown

CVE-2020-25208

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
Attacker Value
Unknown

CVE-2020-17527

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.
Attacker Value
Unknown

CVE-2020-27625

Disclosure Date: November 16, 2020 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
Attacker Value
Unknown

CVE-2020-27626

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
Attacker Value
Unknown

CVE-2020-25209

Disclosure Date: November 16, 2020 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.
Attacker Value
Unknown

CVE-2020-25210

Disclosure Date: November 16, 2020 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.