Security Vulnerabilities
- CVEs Published In August 2021
In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.