First published: Fri Dec 15 2023(Updated: )
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains YouTrack | <2023.3.22268 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50871 has a medium severity rating due to improper authorization checks.
To mitigate CVE-2023-50871, upgrade JetBrains YouTrack to version 2023.3.22268 or later.
CVE-2023-50871 allows unauthorized access to inline comments in thread replies, potentially exposing sensitive information.
CVE-2023-50871 was documented and disclosed in late 2023.
There are no official workarounds for CVE-2023-50871, so updating is the recommended solution.