First published: Thu Oct 10 2024(Updated: )
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains YouTrack | <2024.3.46677 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48902 has a medium severity rating due to its improper access control allowing unauthorized deletion of applications.
To fix CVE-2024-48902, upgrade JetBrains YouTrack to version 2024.3.46677 or later.
CVE-2024-48902 affects users of JetBrains YouTrack versions prior to 2024.3.46677.
CVE-2024-48902 involves improper access control that allows users with project update permissions to delete applications via the API.
CVE-2024-48902 can be easily exploited by users who have legitimate project update permissions, which makes its impact significant.