CVE-2021-25767
https://notcve.org/view.php?id=CVE-2021-25767
In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. En JetBrains YouTrack versiones anteriores a 2020.6.1767, una existencia de un problema podría ser divulgada por medio de una ejecución de comando de YouTrack • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 •
CVE-2021-25766
https://notcve.org/view.php?id=CVE-2021-25766
In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. En JetBrains YouTrack versiones anteriores a 2020.4.4701, se hicieron unas comprobaciones de acceso a recursos inapropiados • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 •
CVE-2020-25208
https://notcve.org/view.php?id=CVE-2020-25208
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions. En JetBrains YouTrack versiones anteriores a 2020.4.4701, un atacante podía enumerar usuarios por medio de la API REST sin los permisos apropiados • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 • CWE-276: Incorrect Default Permissions •
CVE-2021-25765
https://notcve.org/view.php?id=CVE-2021-25765
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. En JetBrains YouTrack versiones anteriores a 2020.4.4701, fue posible un ataque de tipo CSRF por medio de una carga de archivos adjuntos • https://blog.jetbrains.com https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-27624
https://notcve.org/view.php?id=CVE-2020-27624
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF. JetBrains YouTrack versiones anteriores a 2020.3.888, era vulnerable a un ataque de tipo SSRF • https://blog.jetbrains.com https://blog.jetbrains.com/2020/11/16/jetbrains-security-bulletin-q3-2020 • CWE-918: Server-Side Request Forgery (SSRF) •