CVE-2021-25770: Code Injection
Published Feb 3, 2021
·Updated
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
Affected Software
1 affected component
JetBrains YouTrack<2020.5.3123
Event History
Feb 3, 2021
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25770?
The severity of CVE-2021-25770 is critical with a CVSS score of 9.8.
2
What is the vulnerability in JetBrains YouTrack?
The vulnerability in JetBrains YouTrack is a server-side template injection (SSTI) issue.
3
How can server-side template injection in JetBrains YouTrack lead to code execution?
Server-side template injection in JetBrains YouTrack can allow an attacker to inject malicious code into templates, which when executed can lead to arbitrary code execution.
4
Which version of JetBrains YouTrack is affected by CVE-2021-25770?
JetBrains YouTrack before version 2020.5.3123 is affected by CVE-2021-25770.
5
How can I fix CVE-2021-25770?
To fix CVE-2021-25770, it is recommended to update JetBrains YouTrack to version 2020.5.3123 or later.