PT-2024-7203 · Jetbrains · Youtrack

Published

2024-10-10

·

Updated

2024-10-16

·

CVE-2024-48902

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2024.3.46677
Description The issue is related to improper access control in JetBrains YouTrack, allowing users with project update permission to delete applications via API. This could potentially allow a remote attacker to elevate their privileges.
Recommendations For versions prior to 2024.3.46677, update to version 2024.3.46677 or later to resolve the issue. As a temporary workaround, consider restricting access to the API endpoint that allows application deletion to minimize the risk of exploitation.

Fix

Incorrect Authorization

Missing Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-08542
CVE-2024-48902

Affected Products

Youtrack