CVE-2025-24457
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 532
Summary
CVE-2025-24457 is a vulnerability affecting JetBrains YouTrack versions prior to 2024.3.55417. This issue allows permanent tokens to be exposed in logs, potentially leading to unauthorized access and data breaches. Attackers could gain access to sensitive information and perform malicious actions, such as modifying or deleting data, under the privileges of affected users. It is recommended that users of the affected software upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- JetBrains YouTrack
Affected Vendors
- JetBrains