JetBrains YouTrack
cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*, +1 more
- < 2024.3.55417
A vulnerability allowing account takeover was identified in JetBrains YouTrack versions prior to 2024.3.55417. This issue arose from the improper handling of email headers, which enabled spoofing attacks. The vulnerability was exacerbated by the integration of YouTrack with Helpdesk, allowing unauthorized users to manipulate issue comments and attachments.
Exploitation of this vulnerability could lead to unauthorized access to user accounts, allowing attackers to impersonate victims and potentially access or modify sensitive information.
Users can update to JetBrains YouTrack version 2024.3.55417 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.