CVE-2024-50575
- EPSS 21.26%
- Published 28.10.2024 13:15:08
- Last modified 29.10.2024 17:18:26
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
CVE-2024-50574
- EPSS 0.01%
- Published 28.10.2024 13:15:08
- Last modified 29.10.2024 17:16:11
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
CVE-2024-49579
- EPSS 0.07%
- Published 17.10.2024 13:15:14
- Last modified 14.11.2024 19:24:45
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
CVE-2024-48902
- EPSS 0%
- Published 10.10.2024 11:15:13
- Last modified 16.10.2024 16:57:23
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
CVE-2024-47162
- EPSS 0%
- Published 19.09.2024 18:15:10
- Last modified 24.09.2024 17:57:43
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
CVE-2024-47160
- EPSS 0%
- Published 19.09.2024 18:15:10
- Last modified 24.09.2024 18:03:48
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
CVE-2024-47159
- EPSS 0%
- Published 19.09.2024 18:15:09
- Last modified 24.09.2024 18:09:50
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
CVE-2024-38506
- EPSS 0.01%
- Published 18.06.2024 11:15:52
- Last modified 21.11.2024 09:26:06
In JetBrains YouTrack before 2024.2.34646 user without appropriate permissions could enable the auto-attach option for workflows
CVE-2024-38505
- EPSS 0.01%
- Published 18.06.2024 11:15:51
- Last modified 21.11.2024 09:26:06
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
CVE-2024-38504
- EPSS 0.01%
- Published 18.06.2024 11:15:51
- Last modified 21.11.2024 09:26:06
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles