PT-2020-16018 · Jetbrains · Youtrack

Published

2020-11-16

·

Updated

2021-07-21

·

CVE-2020-25209

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2020.3.6638
Description The issue is related to improper access control for some subresources, leading to information disclosure via the REST API.
Recommendations For versions prior to 2020.3.6638, update to version 2020.3.6638 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-25209

Affected Products

Youtrack