In JetBrains YouTrack Confluence... CVE-2019-10100

7.5 AV AC AU C I A
发布: 2019-07-03
修订: 2020-08-24

In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息