PT-2024-2107 · Jetbrains · Jetbrains Youtrack

Published

2024-03-06

·

Updated

2024-12-16

·

CVE-2024-28229

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2024.1.25893
Description The issue is related to insufficient authorization mechanisms in JetBrains YouTrack, allowing a remote attacker to bypass existing security restrictions. This could enable a user without appropriate permissions to restore issues and articles.
Recommendations For versions prior to 2024.1.25893, update to version 2024.1.25893 or later to resolve the issue. As a temporary workaround, consider restricting access to issue and article restoration functionality to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-02003
CVE-2024-28229

Affected Products

Jetbrains Youtrack