CVE-2019-10100
03.07.2019, 19:15
In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.
Vendor | Product | Version |
---|---|---|
jetbrains | youtrack_integration | 𝑥 < 1.8.1.3 |
𝑥
= Vulnerable software versions