First published: Fri Feb 25 2022(Updated: )
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jetbrains Youtrack | <2021.4.40426 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-24442.
CVE-2022-24442 has a severity of critical with a score of 9.8.
JetBrains YouTrack before version 2021.4.40426 is affected by CVE-2022-24442.
CVE-2022-24442 is a Server-Side Template Injection (SSTI) vulnerability that can be exploited via FreeMarker templates in JetBrains YouTrack.
To fix CVE-2022-24442, update JetBrains YouTrack to version 2021.4.40426 or later.