CVE-2024-54154: Path Traversal
Published Dec 4, 2024
·Updated
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
Affected Software
2 affected components
JetBrains YouTrack<2024.3.51866
JetBrains YouTrack<2024.3.51866
Event History
Dec 4, 2024
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54154?
CVE-2024-54154 is classified as a critical vulnerability due to the potential for system takeover.
2
How do I fix CVE-2024-54154?
To fix CVE-2024-54154, upgrade JetBrains YouTrack to version 2024.3.51866 or later.
3
What impact does CVE-2024-54154 have on JetBrains YouTrack?
CVE-2024-54154 allows attackers to exploit path traversal vulnerabilities in the plugin sandbox, leading to possible system takeover.
4
Who is affected by CVE-2024-54154?
Any user running JetBrains YouTrack versions prior to 2024.3.51866 is affected by CVE-2024-54154.
5
When was CVE-2024-54154 discovered?
CVE-2024-54154 was reported and acknowledged by JetBrains prior to the release of the fix in version 2024.3.51866.