JetBrains

YouTrack

184 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 30.09.2026 15:17:47
  • Zuletzt bearbeitet 02.10.2026 20:36:57

In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings

  • EPSS 0.21%
  • Veröffentlicht 30.09.2026 15:17:46
  • Zuletzt bearbeitet 02.10.2026 20:42:55

In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export

  • EPSS 0.27%
  • Veröffentlicht 07.09.2026 17:17:28
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

  • EPSS 0.17%
  • Veröffentlicht 07.09.2026 17:17:28
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

  • EPSS 0.16%
  • Veröffentlicht 07.09.2026 17:17:28
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

  • EPSS 0.15%
  • Veröffentlicht 07.09.2026 17:17:28
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin

  • EPSS 0.2%
  • Veröffentlicht 07.09.2026 17:17:27
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

  • EPSS 0.2%
  • Veröffentlicht 07.09.2026 17:17:27
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

  • EPSS 0.17%
  • Veröffentlicht 07.09.2026 17:17:27
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

  • EPSS 0.14%
  • Veröffentlicht 07.09.2026 17:17:27
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads