CVE-2024-54155: Medium severity jetbrains youtrack vulnerability
Published Dec 4, 2024
·Updated
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
Affected Software
2 affected components
JetBrains YouTrack<2024.3.51866
JetBrains YouTrack<2024.3.51866
Event History
Dec 4, 2024
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54155?
CVE-2024-54155 has a moderate severity rating due to improper access control in JetBrains YouTrack.
2
How do I fix CVE-2024-54155?
To fix CVE-2024-54155, upgrade JetBrains YouTrack to version 2024.3.51866 or later.
3
What are the risks associated with CVE-2024-54155?
The risks of CVE-2024-54155 include unauthorized access to project names during app import, which can lead to potential data exposure.
4
Which versions of JetBrains YouTrack are affected by CVE-2024-54155?
CVE-2024-54155 affects all versions of JetBrains YouTrack prior to 2024.3.51866.
5
What type of vulnerability is CVE-2024-54155?
CVE-2024-54155 is classified as an access control vulnerability.