Stored XSS Vulnerability in JetBrains YouTrack Markdown Rendering Engine
CVE-2023-35054

5.4MEDIUM

Key Information:

Vendor

JetBrains

Status
Vendor
CVE Published:
12 June 2023

What is CVE-2023-35054?

In JetBrains YouTrack versions before 2023.1.10518, a security vulnerability was identified in the Markdown-rendering engine that allows for stored Cross-Site Scripting (XSS). By exploiting this flaw, attackers can potentially inject malicious scripts into content that is stored and rendered in the application, leading to unauthorized actions or data exposure when users interact with the affected content.

Affected Version(s)

YouTrack 0 < 2023.1.10518

References

EPSS Score

25% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.