CVE-2024-54157: Medium severity jetbrains youtrack vulnerability
Published Dec 4, 2024
·Updated
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
Affected Software
2 affected components
JetBrains YouTrack<2024.3.52635
JetBrains YouTrack<2024.3.52635
Event History
Dec 4, 2024
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54157?
CVE-2024-54157 has the potential for a denial of service attack due to a Regular Expression Denial of Service (ReDoS).
2
How do I fix CVE-2024-54157?
To fix CVE-2024-54157, upgrade JetBrains YouTrack to version 2024.3.52635 or later.
3
Which versions of JetBrains YouTrack are affected by CVE-2024-54157?
Versions of JetBrains YouTrack prior to 2024.3.52635 are affected by CVE-2024-54157.
4
What type of vulnerability is CVE-2024-54157?
CVE-2024-54157 is a Regular Expression Denial of Service vulnerability.
5
Can CVE-2024-54157 allow attackers to exploit my application?
Yes, CVE-2024-54157 can potentially be exploited by attackers to cause a denial of service by exploiting the vulnerable RegExp.