CVE-2025-54527

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/07/2025
Last modified:
01/12/2025

Description

In JetBrains YouTrack before 2025.2.86935, <br /> 2025.2.87167, <br /> 2025.3.87341, <br /> 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:* 2025.2.86935 (excluding)
cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:* 2025.2.87000 (including) 2025.2.87167 (excluding)
cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:* 2025.3 (including) 2025.3.87341 (excluding)


References to Advisories, Solutions, and Tools