PT-2024-7356 · Jetbrains · Jetbrains Youtrack
Published
2024-10-17
·
Updated
2024-11-14
·
CVE-2024-49579
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
JetBrains YouTrack versions prior to 2024.3.47197
Description:
The issue is related to insufficient validation of the communication channel source in the iframe plugin of JetBrains YouTrack. This can allow an attacker to execute arbitrary JavaScript code and make unauthorized API requests.
Recommendations:
For versions prior to 2024.3.47197, update to version 2024.3.47197 or later to resolve the issue. As a temporary workaround, consider disabling the iframe plugin until a patch is available. Restrict access to the iframe plugin to minimize the risk of exploitation. Avoid using the iframe plugin in the affected API endpoints until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetbrains Youtrack