CVE-2025-64685: High severity JetBrains YouTrack vulnerability
Published Nov 10, 2025
·Updated
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
Affected Software
2 affected components
JetBrains YouTrack<2025.3.104432
JetBrains YouTrack<2025.3.104432
Event History
Nov 10, 2025
CVE Published
via MITRE·01:27 PM
Data Sourced
via MITRE·01:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64685?
CVE-2025-64685 is classified as a medium severity vulnerability due to its potential for data disclosure.
2
How do I fix CVE-2025-64685?
To fix CVE-2025-64685, upgrade JetBrains YouTrack to version 2025.3.104432 or later.
3
What kind of data is at risk in CVE-2025-64685?
CVE-2025-64685 poses a risk of exposing sensitive user data due to missing TLS certificate validation.
4
Which software versions are affected by CVE-2025-64685?
CVE-2025-64685 affects JetBrains YouTrack versions prior to 2025.3.104432.
5
Is there a workaround for CVE-2025-64685 if I can't update right away?
There are no documented workarounds for CVE-2025-64685; it is strongly recommended to apply the update.