CVE-2019-12866: Critical severity jetbrains youtrack vulnerability
Published Jul 3, 2019
·Updated
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.
Affected Software
1 affected component
JetBrains YouTrack<2018.4.49168
Event History
Jul 3, 2019
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12866?
CVE-2019-12866 is classified as a low severity vulnerability due to its nature.
2
What does CVE-2019-12866 exploit?
CVE-2019-12866 exploits an Insecure Direct Object Reference coupled with an Authorization Bypass.
3
Which versions of JetBrains YouTrack are affected by CVE-2019-12866?
CVE-2019-12866 affects JetBrains YouTrack versions prior to 2018.4.49168.
4
How do I fix CVE-2019-12866?
The fix for CVE-2019-12866 is to upgrade your JetBrains YouTrack installation to version 2018.4.49168 or later.
5
Was CVE-2019-12866 patched, and when?
Yes, CVE-2019-12866 was patched in the JetBrains YouTrack version 2018.4.49168.