In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15821
Reference (s):
- https://blog.jetbrains.com
- https://blog.jetbrains.com/blog/2020/08/06/jetbrains-security-bulletin-q2-2020/

