JetBrains YouTrack Missing Permission Checks Allow Unauthorized Issue Deletion

Vulnerability

A vulnerability in JetBrains YouTrack prior to version 2025.1.76253 allows users to delete issues without proper authorization. This issue arises from inadequate permission checks in the YouTrack API, enabling unauthorized deletion of issues.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of issues, potentially causing data loss and disruption of project management activities.

Remediation

Users can upgrade to JetBrains YouTrack version 2025.1.76253 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.