PT-2024-3956 · Jetbrains · Jetbrains Youtrack

Published

2024-05-16

·

Updated

2024-05-29

·

CVE-2024-35299

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2024.1.29548
Description The issue is related to the implementation of the SMTPS protocol in JetBrains YouTrack, which lacks proper certificate hostname validation. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to 2024.1.29548, update to version 2024.1.29548 or later to resolve the issue. As a temporary workaround, consider restricting the use of SMTPS protocol communication until a patch is applied.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04370
CVE-2024-35299

Affected Products

Jetbrains Youtrack