CVE-2024-54158: Medium severity jetbrains youtrack vulnerability
Published Dec 4, 2024
·Updated
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
Affected Software
2 affected components
JetBrains YouTrack<2024.3.52635
JetBrains YouTrack<2024.3.52635
Event History
Dec 4, 2024
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54158?
CVE-2024-54158 is classified as a medium severity vulnerability related to potential spoofing attacks in JetBrains YouTrack.
2
How do I fix CVE-2024-54158?
To fix CVE-2024-54158, upgrade JetBrains YouTrack to version 2024.3.52635 or later.
3
What types of attacks are possible due to CVE-2024-54158?
CVE-2024-54158 allows for potential spoofing attacks due to the lack of Punycode encoding.
4
Which versions of JetBrains YouTrack are affected by CVE-2024-54158?
CVE-2024-54158 affects all versions of JetBrains YouTrack prior to 2024.3.52635.
5
Is there a workaround for CVE-2024-54158?
Currently, there is no documented workaround for CVE-2024-54158; updating to the latest version is recommended.