CVE-2024-28228
- EPSS 0.48%
- Veröffentlicht 07.03.2024 12:15:46
- Zuletzt bearbeitet 16.12.2024 15:06:31
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
CVE-2024-22370
- EPSS 0.41%
- Veröffentlicht 09.01.2024 10:15:23
- Zuletzt bearbeitet 21.11.2024 08:56:08
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
CVE-2023-50871
- EPSS 0.45%
- Veröffentlicht 15.12.2023 14:15:15
- Zuletzt bearbeitet 21.11.2024 08:37:27
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
CVE-2023-38068
- EPSS 0.55%
- Veröffentlicht 12.07.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:12:47
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
CVE-2023-35053
- EPSS 0.62%
- Veröffentlicht 12.06.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:53
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
CVE-2023-35054
- EPSS 0.97%
- Veröffentlicht 12.06.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:53
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
CVE-2022-28649
- EPSS 0.39%
- Veröffentlicht 05.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:39
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue description
CVE-2022-28650
- EPSS 0.62%
- Veröffentlicht 05.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:39
In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
CVE-2022-28648
- EPSS 1.37%
- Veröffentlicht 05.04.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:39
In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
CVE-2022-24442
- EPSS 3.68%
- Veröffentlicht 25.02.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:25
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.