CVE-2025-48391: High severity jetbrains youtrack vulnerability
Published May 20, 2025
·Updated
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
Affected Software
2 affected components
JetBrains YouTrack<2025.1.76253
JetBrains YouTrack<2025.1.76253
Event History
May 20, 2025
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48391?
CVE-2025-48391 is considered a critical vulnerability due to the potential for unauthorized deletion of issues.
2
How do I fix CVE-2025-48391?
To mitigate CVE-2025-48391, upgrade JetBrains YouTrack to version 2025.1.76253 or later.
3
What impact does CVE-2025-48391 have on JetBrains YouTrack users?
CVE-2025-48391 allows users without proper permissions to delete issues, potentially leading to data loss.
4
What versions of JetBrains YouTrack are affected by CVE-2025-48391?
CVE-2025-48391 affects JetBrains YouTrack versions prior to 2025.1.76253.
5
Are there any workarounds for CVE-2025-48391 until a patch is applied?
There are no official workarounds for CVE-2025-48391; upgrading to the fixed version is recommended.