In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
Link | Tags |
---|---|
https://www.jetbrains.com/privacy-security/issues-fixed/ | vendor advisory |