First published: Thu Mar 07 2024(Updated: )
In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains YouTrack | <2024.1.25893 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28230 is classified as a medium severity vulnerability due to improper access controls.
To fix CVE-2024-28230, users should upgrade to JetBrains YouTrack version 2024.1.25893 or later.
CVE-2024-28230 allows users to attach or detach workflows to projects without having project admin permissions, potentially compromising project security.
JetBrains YouTrack versions prior to 2024.1.25893 are affected by CVE-2024-28230.
There are no documented temporary workarounds for CVE-2024-28230, and updating is recommended.