CVE-2024-54156: Medium severity jetbrains youtrack vulnerability
Published Dec 4, 2024
·Updated
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
Affected Software
2 affected components
JetBrains YouTrack<2024.3.52635
JetBrains YouTrack<2024.3.52635
Event History
Dec 4, 2024
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54156?
CVE-2024-54156 has been categorized as a medium severity vulnerability.
2
How do I fix CVE-2024-54156?
To mitigate CVE-2024-54156, upgrade JetBrains YouTrack to version 2024.3.52635 or later.
3
What type of attack does CVE-2024-54156 involve?
CVE-2024-54156 involves a prototype pollution attack vulnerability.
4
Which software versions are affected by CVE-2024-54156?
CVE-2024-54156 affects versions of JetBrains YouTrack prior to 2024.3.52635.
5
What functions are vulnerable in CVE-2024-54156?
Multiple merge functions in JetBrains YouTrack are vulnerable as noted in CVE-2024-54156.