PT-2024-3956 · Jetbrains · Jetbrains Youtrack
Published
2024-05-16
·
Updated
2024-05-29
·
CVE-2024-35299
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JetBrains YouTrack versions prior to 2024.1.29548
Description
The issue is related to the implementation of the SMTPS protocol in JetBrains YouTrack, which lacks proper certificate hostname validation. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For versions prior to 2024.1.29548, update to version 2024.1.29548 or later to resolve the issue. As a temporary workaround, consider restricting the use of SMTPS protocol communication until a patch is applied.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetbrains Youtrack