PT-2025-46158 · Jetbrains · Jetbrains Youtrack

Published

2025-11-10

·

Updated

2025-11-21

·

CVE-2025-64689

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2025.3.104432
Description A misconfiguration within the internal component called Junie in JetBrains YouTrack can result in the exposure of the global Junie token. This token is used for internal authentication within YouTrack, and its compromise could allow an attacker to obtain authentication credentials.
Recommendations Update JetBrains YouTrack to version 2025.3.104432 or later.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-14649
CVE-2025-64689

Affected Products

Jetbrains Youtrack