JetBrains

YouTrack

184 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 07.09.2026 17:17:26
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

  • EPSS 0.17%
  • Veröffentlicht 07.09.2026 17:17:26
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

  • EPSS 0.13%
  • Veröffentlicht 07.09.2026 17:17:26
  • Zuletzt bearbeitet 08.09.2026 15:30:03

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

  • EPSS 0.36%
  • Veröffentlicht 07.09.2026 17:17:25
  • Zuletzt bearbeitet 09.09.2026 05:18:19

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

  • EPSS 0.22%
  • Veröffentlicht 17.08.2026 15:54:37
  • Zuletzt bearbeitet 15.09.2026 16:14:58

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

  • EPSS 0.2%
  • Veröffentlicht 17.08.2026 15:54:36
  • Zuletzt bearbeitet 15.09.2026 17:48:37

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 15:54:36
  • Zuletzt bearbeitet 15.09.2026 17:49:19

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

  • EPSS 0.8%
  • Veröffentlicht 17.08.2026 15:54:36
  • Zuletzt bearbeitet 15.09.2026 17:45:36

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

  • EPSS 0.21%
  • Veröffentlicht 17.08.2026 15:54:35
  • Zuletzt bearbeitet 15.09.2026 17:47:29

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

  • EPSS 0.86%
  • Veröffentlicht 17.08.2026 15:54:35
  • Zuletzt bearbeitet 15.09.2026 17:47:56

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint