CVE-2025-54527

In JetBrains YouTrack before 2025.2.86935, 
2025.2.87167, 
2025.3.87341, 
2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
JetBrainsCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
jetbrainsyoutrack
𝑥
< 2025.2.86935
jetbrainsyoutrack
2025.2.87000 ≤
𝑥
< 2025.2.87167
jetbrainsyoutrack
2025.3 ≤
𝑥
< 2025.3.87341
𝑥
= Vulnerable software versions