CVE-2025-24458: High severity jetbrains youtrack vulnerability
Published Jan 21, 2025
·Updated
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
Affected Software
2 affected components
JetBrains YouTrack<2024.3.55417
JetBrains YouTrack<2024.3.55417
Event History
Jan 21, 2025
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Nov 29, 57087
Event
via FIRST·02:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-24458?
The severity of CVE-2025-24458 is classified as high due to its potential for account takeover.
2
How do I fix CVE-2025-24458?
To fix CVE-2025-24458, upgrade JetBrains YouTrack to version 2024.3.55417 or later.
3
What causes CVE-2025-24458?
CVE-2025-24458 is caused by the ability to execute account takeover via spoofed email and Helpdesk integration.
4
Which versions of JetBrains YouTrack are affected by CVE-2025-24458?
CVE-2025-24458 affects all versions of JetBrains YouTrack prior to 2024.3.55417.
5
Is there a workaround for CVE-2025-24458?
There are no specific workarounds for CVE-2025-24458; the recommended action is to update YouTrack.