2.2

CVSS3.1

CVE-2024-8013 - CSFLE and Queryable Encryption self-lookup may fail to encrypt values in subpipelines

A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue affects mongocryptd…

πŸ“… Published: Oct. 28, 2024, 12:58 p.m. πŸ”„ Last Modified: Oct. 31, 2024, 1:33 p.m.

4.6

CVSS3.1

CVE-2024-50582 -

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:16 p.m.

4.6

CVSS3.1

CVE-2024-50581 -

In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:17 p.m.

4.6

CVSS3.1

CVE-2024-50580 -

In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:17 p.m.

4.6

CVSS3.1

CVE-2024-50579 -

In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:17 p.m.

4.6

CVSS3.1

CVE-2024-50578 -

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:17 p.m.

4.6

CVSS3.1

CVE-2024-50577 -

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:18 p.m.

4.6

CVSS3.1

CVE-2024-50576 -

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:18 p.m.

4.6

CVSS3.1

CVE-2024-50575 -

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:18 p.m.

5.3

CVSS3.1

CVE-2024-50574 -

In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

πŸ“… Published: Oct. 28, 2024, 12:55 p.m. πŸ”„ Last Modified: Oct. 29, 2024, 5:16 p.m.
Total resulsts: 349182
Page 8123 of 34,919
Β« previous page Β» next page
Filters