First published: Mon Oct 19 2020(Updated: )
In JetBrains YouTrack before 2020.2.10514, SSRF is possible because URL filtering can be escaped.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Youtrack | <2020.2.10514 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this JetBrains YouTrack vulnerability is CVE-2020-15822.
CVE-2020-15822 has a severity rating of 7.3, which is considered high.
CVE-2020-15822 is a vulnerability in JetBrains YouTrack before 2020.2.10514 that allows server-side request forgery (SSRF) due to escaping URL filtering.
JetBrains YouTrack versions up to and excluding 2020.2.10514 are affected by CVE-2020-15822.
Yes, a security bulletin for this vulnerability can be found at <a href='https://blog.jetbrains.com/blog/2020/08/06/jetbrains-security-bulletin-q2-2020/'>https://blog.jetbrains.com/blog/2020/08/06/jetbrains-security-bulletin-q2-2020/</a>.