Show filters
249 Total Results
Displaying 141-150 of 249
Sort by:
Attacker Value
Unknown

CVE-2020-24366

Disclosure Date: November 16, 2020 (last updated November 28, 2024)
Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.
Attacker Value
Unknown

CVE-2020-27624

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
Attacker Value
Unknown

CVE-2019-17566

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Attacker Value
Unknown

CVE-2020-15822

Disclosure Date: October 19, 2020 (last updated February 22, 2025)
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
Attacker Value
Unknown

CVE-2020-13943

Disclosure Date: October 12, 2020 (last updated November 28, 2024)
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Attacker Value
Unknown

CVE-2020-24618

Disclosure Date: August 27, 2020 (last updated November 28, 2024)
In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
Attacker Value
Unknown

CVE-2020-15823

Disclosure Date: August 08, 2020 (last updated February 21, 2025)
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
Attacker Value
Unknown

CVE-2020-15821

Disclosure Date: August 08, 2020 (last updated February 21, 2025)
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
Attacker Value
Unknown

CVE-2020-15819

Disclosure Date: August 08, 2020 (last updated February 21, 2025)
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
Attacker Value
Unknown

CVE-2020-15820

Disclosure Date: August 08, 2020 (last updated November 28, 2024)
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.