CVE-2024-38505: High severity jetbrains youtrack vulnerability
Published Jun 18, 2024
·Updated
In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site
Affected Software
1 affected component
JetBrains YouTrack<2024.2.34646
Event History
Jun 18, 2024
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38505?
CVE-2024-38505 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-38505?
To fix CVE-2024-38505, upgrade JetBrains YouTrack to version 2024.2.34646 or later.
3
What type of vulnerability is CVE-2024-38505?
CVE-2024-38505 is an information disclosure vulnerability involving user access tokens.
4
What versions of JetBrains YouTrack are affected by CVE-2024-38505?
CVE-2024-38505 affects all versions of JetBrains YouTrack prior to 2024.2.34646.
5
What is the impact of CVE-2024-38505?
The impact of CVE-2024-38505 is that user access tokens may be sent to a third-party site, potentially leading to unauthorized access.