Security Vulnerability in YouTrack Allows Access to Global App Config Data Without Permissions
CVE-2024-47160

5.3MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
19 September 2024

What is CVE-2024-47160?

The vulnerability in JetBrains YouTrack, prior to version 2024.3.44799, allows unauthorized access to global application configuration data. This oversight in permission management could enable attackers to exploit sensitive configurations, potentially compromising the integrity and security of the entire application. Organizations using affected versions are urged to update promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

YouTrack 0 < 2024.3.44799

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-47160 : Security Vulnerability in YouTrack Allows Access to Global App Config Data Without Permissions