PT-2024-9173 · Jetbrains · Youtrack

Published

2024-11-29

·

Updated

2025-01-30

·

CVE-2024-54158

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: JetBrains YouTrack versions prior to 2024.3.52635
Description: The issue is related to a potential spoofing attack due to the lack of Punycode encoding in JetBrains YouTrack. This could allow a remote attacker to conduct spoofing attacks. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations: For versions prior to 2024.3.52635, update to version 2024.3.52635 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2024-10860
CVE-2024-54158

Affected Products

Youtrack