CVE-2024-35299: High severity jetbrains youtrack vulnerability
Published May 16, 2024
·Updated
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
Affected Software
2 affected components
JetBrains YouTrack<2024.1.29548
JetBrains YouTrack<2024.1.29548
Event History
May 16, 2024
CVE Published
via MITRE·10:31 AM
Data Sourced
via MITRE·10:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35299?
CVE-2024-35299 is rated as a moderate severity vulnerability due to improper hostname validation in the SMTPS protocol.
2
How do I fix CVE-2024-35299?
To fix CVE-2024-35299, upgrade JetBrains YouTrack to version 2024.1.29548 or later.
3
What impact does CVE-2024-35299 have on JetBrains YouTrack?
CVE-2024-35299 can lead to potential Man-in-the-Middle attacks due to lack of proper certificate hostname validation.
4
Which versions of JetBrains YouTrack are affected by CVE-2024-35299?
All versions of JetBrains YouTrack prior to 2024.1.29548 are affected by CVE-2024-35299.
5
Is there any workaround for CVE-2024-35299?
There are no known workarounds for CVE-2024-35299; upgrading to the fixed version is recommended.