CVE Vulnerabilities

CVE-2020-24618

Published: Aug 27, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

Affected Software

NameVendorStart VersionEnd Version
YoutrackJetbrains*2019.1.65514 (excluding)
YoutrackJetbrains2019.2.0 (including)2019.2.65515 (excluding)
YoutrackJetbrains2019.3 (including)2019.3.65516 (excluding)
YoutrackJetbrains2020.1 (including)2020.1.11011 (excluding)
YoutrackJetbrains2020.2 (including)2020.2.11008 (excluding)
YoutrackJetbrains2020.3 (including)2020.3.4313 (excluding)

References