CVE-2019-16171: XSS
Published Oct 2, 2019
·Updated
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
Affected Software
1 affected component
JetBrains YouTrack<=2019.2.56594
Event History
Oct 2, 2019
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16171?
CVE-2019-16171 has a medium severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2019-16171?
To fix CVE-2019-16171, upgrade JetBrains YouTrack to version 2019.2.56600 or later.
3
What types of attacks can CVE-2019-16171 enable?
CVE-2019-16171 can enable stored cross-site scripting attacks which might allow an attacker to execute malicious scripts in the context of a user's browser.
4
Who is affected by CVE-2019-16171?
Users of JetBrains YouTrack versions up to 2019.2.56594 are affected by CVE-2019-16171.
5
What specific component in YouTrack is vulnerable in CVE-2019-16171?
CVE-2019-16171 specifically affects the issue page of JetBrains YouTrack where stored XSS vulnerabilities were identified.