CVE-2024-54153: Medium severity jetbrains youtrack vulnerability
Published Dec 4, 2024
·Updated
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
Affected Software
2 affected components
JetBrains YouTrack<2024.3.51866
JetBrains YouTrack<2024.3.51866
Event History
Dec 4, 2024
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54153?
CVE-2024-54153 is categorized as a critical severity vulnerability due to its potential for sensitive data exposure.
2
How do I fix CVE-2024-54153?
To mitigate CVE-2024-54153, upgrade JetBrains YouTrack to version 2024.3.51867 or later.
3
What kind of attack is CVE-2024-54153 associated with?
CVE-2024-54153 is associated with unauthorized access to database backups through a vulnerable query parameter.
4
Which versions of JetBrains YouTrack are affected by CVE-2024-54153?
CVE-2024-54153 affects all versions of JetBrains YouTrack up to, but not including, version 2024.3.51866.
5
Can CVE-2024-54153 be exploited remotely?
Yes, CVE-2024-54153 can be exploited remotely, allowing unauthenticated attackers to download sensitive database backups.