Certificate Hostname Validation Flaw in YouTrack Before 2024.1.29548
CVE-2024-35299
7.5HIGH
What is CVE-2024-35299?
In JetBrains YouTrack, prior to version 2024.1.29548, an issue was identified in the SMTPS protocol that resulted in inadequate validation of certificate hostnames. This vulnerability potentially allows attackers to exploit improper certificate validation, leading to potential security breaches. Users are highly encouraged to update their software to the latest version to safeguard against these risks.
Affected Version(s)
YouTrack 0 < 2024.1.29548