CVE-2021-25765: CSRF
Published Feb 3, 2021
·Updated
In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
Affected Software
1 affected component
JetBrains YouTrack<2020.4.4701
Event History
Feb 3, 2021
CVE Published
via MITRE·03:26 PM
Data Sourced
via MITRE·03:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25765.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In JetBrains YouTrack before 2020.4.4701 CSRF via attachment upload was possible.'
3
What is the severity of CVE-2021-25765?
The severity of CVE-2021-25765 is high with a CVSS score of 8.8.
4
How does CVE-2021-25765 affect JetBrains YouTrack?
CVE-2021-25765 affects JetBrains YouTrack versions before 2020.4.4701.
5
How can I fix the vulnerability CVE-2021-25765 in JetBrains YouTrack?
To fix the vulnerability CVE-2021-25765, update JetBrains YouTrack to version 2020.4.4701 or later.