First published: Wed Jul 03 2019(Updated: )
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains YouTrack | <2018.4.49168 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12852 has been assessed with a high severity rating due to its potential for Server-Side Request Forgery (SSRF) attacks.
To fix CVE-2019-12852, update your JetBrains YouTrack server to version 2018.4.49168 or later.
CVE-2019-12852 affects JetBrains YouTrack versions prior to 2018.4.49168.
An SSRF attack allows an attacker to make requests from the server to internal or external systems potentially exposing sensitive data.
Yes, CVE-2019-12852 was fixed in JetBrains YouTrack version 2018.4.49168.