CVE-2019-10100

CRITICAL

JetBrains YouTrack Confluence <1.8.1.3 - SSRF

Title source: llm
STIX 2.1

Description

In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0001
EPSS Percentile 1.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
jetbrains/youtrack_integration < 1.8.1.3
Published Jul 03, 2019
Tracked Since Feb 18, 2026