216.73.217.22

CVE-2025-54527

· Published 28/07/2025 17:15 · Modified 29/07/2025 14:14

Labels: CVE-2025-54527 2025-07-28CVE-2025-54527CWE-1021[email protected]

Essential information

Published
28/07/2025 17:15
Modified
29/07/2025 14:14
Author
Creator
CVSS
6.1 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jetbrains / youtrack cpe:2.3:a:jetbrains:youtrack:<2025.2.86935:*:*:*:*:*:*:*
jetbrains / youtrack cpe:2.3:a:jetbrains:youtrack:2025.2.87167:*:*:*:*:*:*:*
jetbrains / youtrack cpe:2.3:a:jetbrains:youtrack:2025.3.87341:*:*:*:*:*:*:*
jetbrains / youtrack cpe:2.3:a:jetbrains:youtrack:2025.3.87344:*:*:*:*:*:*:*

References