CVE-2022-24442: Code Injection
Published Feb 25, 2022
·Updated
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Affected Software
1 affected component
JetBrains YouTrack<2021.4.40426
Event History
Feb 25, 2022
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24442.
2
What is the severity of CVE-2022-24442?
CVE-2022-24442 has a severity of critical with a score of 9.8.
3
What is the affected software?
JetBrains YouTrack before version 2021.4.40426 is affected by CVE-2022-24442.
4
How does CVE-2022-24442 work?
CVE-2022-24442 is a Server-Side Template Injection (SSTI) vulnerability that can be exploited via FreeMarker templates in JetBrains YouTrack.
5
How can I fix CVE-2022-24442?
To fix CVE-2022-24442, update JetBrains YouTrack to version 2021.4.40426 or later.