CVE-2023-35054: XSS
Published Jun 12, 2023
·Updated
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
Affected Software
1 affected component
JetBrains YouTrack<2023.1.10518
Event History
Jun 12, 2023
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this JetBrains YouTrack vulnerability?
The vulnerability ID for this JetBrains YouTrack vulnerability is CVE-2023-35054.
2
What is the severity of CVE-2023-35054?
The severity of CVE-2023-35054 is medium with a CVSS score of 5.4.
3
What software version is affected by CVE-2023-35054?
The software version affected by CVE-2023-35054 is JetBrains YouTrack up to version 2023.1.10518.
4
What is the impact of CVE-2023-35054?
CVE-2023-35054 allows for stored cross-site scripting (XSS) attacks in the Markdown-rendering engine of JetBrains YouTrack.
5
How can I fix CVE-2023-35054 in JetBrains YouTrack?
To fix CVE-2023-35054 in JetBrains YouTrack, update to version 2023.1.10518 or newer.