5.4
CVE-2025-64690 -
In JetBrains YouTrack before 2025.3.104432 insecure Junie configuration could lead to data exposure and unauthorized changes
9.6
CVE-2025-64689 -
In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token
7.4
CVE-2025-64688 -
In JetBrains YouTrack before 2025.3.104432 missing VCS URL validation allowed delegation to unauthorized repositories from the Junie widget
5.4
CVE-2025-64687 -
In JetBrains YouTrack before 2025.3.104432 improper access control allowed modify MCP tool logic
3.1
CVE-2025-64686 -
In JetBrains YouTrack before 2025.3.104432 missing user principal cleanup led to reuse of incorrect authorization context
8.1
CVE-2025-64685 -
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
4.5
CVE-2025-64684 -
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
5.3
CVE-2025-64683 -
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
2.7
CVE-2025-64682 -
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
2.7
CVE-2025-64681 -
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations