First published: Wed Feb 03 2021(Updated: )
In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Youtrack | <2020.4.4701 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-25208.
The severity of CVE-2020-25208 is medium, with a value of 5.3.
CVE-2020-25208 allows an attacker to enumerate users via the REST API without appropriate permissions in JetBrains YouTrack before version 2020.4.4701.
To fix CVE-2020-25208, you should update JetBrains YouTrack to version 2020.4.4701 or later.
You can find more information about CVE-2020-25208 in the JetBrains Security Bulletin Q4 2020.