Page 5 of 92 results (0.026 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

25 Feb 2022 — In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. En JetBrains YouTrack versiones anteriores a 2021.4.31698, un usuario con permisos de sólo lectura podía establecer un logotipo personalizado. • https://blog.jetbrains.com • CWE-276: Incorrect Default Permissions •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

09 Nov 2021 — In JetBrains YouTrack before 2021.3.21051, stored XSS is possible. En JetBrains YouTrack versiones anteriores a 2021.3.21051, un ataque de tipo XSS almacenado es posible • https://blog.jetbrains.com/blog/2021/11/08/jetbrains-security-bulletin-q3-2021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

09 Nov 2021 — JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. JetBrains YouTrack versiones anteriores a 2021.3.23639, es vulnerable a una inyección de encabezados de Host • https://blog.jetbrains.com/blog/2021/11/08/jetbrains-security-bulletin-q3-2021 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

09 Nov 2021 — JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS. JetBrains YouTrack versiones anteriores a 2021.3.24402, es vulnerable a un ataque de tipo XSS almacenado • https://blog.jetbrains.com/blog/2021/11/08/jetbrains-security-bulletin-q3-2021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

06 Aug 2021 — In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. En JetBrains YouTrack versiones anteriores a 2021.3.21051, un usuario podía visualizar tableros sin tener los permisos correspondientes • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

06 Aug 2021 — In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. En JetBrains YouTrack versiones anteriores a 2021.2.16363, era usado un PRNG no seguro • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

06 Aug 2021 — In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. En JetBrains YouTrack versiones anteriores a 2021.2.16363, unas contraseñas de usuarios del sistema estaban cifradas con SHA-256 • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-916: Use of Password Hash With Insufficient Computational Effort •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

06 Aug 2021 — In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. En JetBrains YouTrack versiones anteriores a 2021.2.17925, era posible un ataque de tipo XSS almacenado • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

06 Aug 2021 — In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. En JetBrains YouTrack versiones anteriores a 2021.2.16363, eran usadas comparaciones no seguras en el tiempo • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 • CWE-697: Incorrect Comparison •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

06 Aug 2021 — In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient. En JetBrains YouTrack versiones anteriores a 2021.1.11111, el sandboxing en los workflows era insuficiente • https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021 •