First published: Wed Jul 03 2019(Updated: )
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Youtrack Integration | <1.8.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.