« Volver al listado

Jetbrains

Jetbrains Youtrack: vulnerabilidades y CVE

Jetbrains Youtrack tiene 179 vulnerabilidades publicadas, 82 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE179
Últimos 12 meses82
Críticas15
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-103497Media (5.5)0.15%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVE-2026-103496Media (5.4)0.14%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVE-2026-103495Media (4.3)0.19%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVE-2026-103494Media (6.6)0.21%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVE-2026-103493Alta (8.1)0.22%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2026-103492Media (6.5)0.68%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVE-2026-103491Media (6.5)0.20%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVE-2026-103490Alta (7.2)0.43%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
CVE-2026-103489Media (5.4)0.14%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVE-2026-103488Alta (7.1)0.28%—1 oct 2026
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVE-2026-100280Media (4.3)0.17%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
CVE-2026-100279Media (6.5)0.25%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
CVE-2026-100278Media (4.9)0.24%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
CVE-2026-100277Crítica (9.8)0.28%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
CVE-2026-100276Alta (7.5)0.22%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
CVE-2026-100275Media (4.8)0.19%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-100274Media (6.5)0.84%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
CVE-2026-100273Crítica (9.8)0.30%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
CVE-2026-100272Media (4.9)0.29%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues
CVE-2026-100271Baja (2.7)0.23%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects
CVE-2026-100270Baja (2.7)0.17%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations
CVE-2026-100269Media (4.3)0.20%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
CVE-2026-100268Baja (2.7)0.23%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
CVE-2026-100267Media (5.9)0.29%—30 sept 2026
In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
CVE-2026-100264Baja (2.7)0.23%—30 sept 2026
In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
CVE-2026-100263Media (6.1)0.19%—30 sept 2026
In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-100262Alta (7.1)0.21%—30 sept 2026
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
CVE-2026-100261Media (5.4)0.18%—30 sept 2026
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVE-2026-100260Media (5.3)0.27%—30 sept 2026
In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
CVE-2026-100259Media (4.3)0.19%—30 sept 2026
In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services32
  2. T1190 Exploit Public-Facing Application16
  3. T1078 Valid Accounts15
  4. T1005 Data from Local System8
  5. T1059.007 JavaScript6
  6. T1189 Drive-by Compromise5

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Jetbrains