Authorization Check Bypass in JetBrains YouTrack Product
CVE-2023-50871
4.3MEDIUM
What is CVE-2023-50871?
In JetBrains YouTrack, prior to version 2023.3.22268, an authorization check was inadvertently omitted for inline comments in thread replies. This oversight may allow unauthorized users to access or manipulate comments, posing a potential risk to data integrity and confidentiality within project management workflows.
Affected Version(s)
YouTrack 0 < 2023.3.22268