PT-2025-5364 · Jetbrains · Youtrack

Published

2025-01-21

·

Updated

2025-01-30

·

CVE-2025-24458

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2024.3.55417
Description The issue allows for account takeover via spoofed email and Helpdesk integration. This enables unauthorized access to accounts, potentially leading to data breaches or other malicious activities. The estimated number of affected devices is not provided.
Recommendations JetBrains YouTrack versions prior to 2024.3.55417: Update to version 2024.3.55417 or later to resolve the issue.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2025-01198
CVE-2025-24458

Affected Products

Youtrack