First published: Mon Jun 12 2023(Updated: )
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Youtrack | <2023.1.10518 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this JetBrains YouTrack vulnerability is CVE-2023-35054.
The severity of CVE-2023-35054 is medium with a CVSS score of 5.4.
The software version affected by CVE-2023-35054 is JetBrains YouTrack up to version 2023.1.10518.
CVE-2023-35054 allows for stored cross-site scripting (XSS) attacks in the Markdown-rendering engine of JetBrains YouTrack.
To fix CVE-2023-35054 in JetBrains YouTrack, update to version 2023.1.10518 or newer.