CVE-2025-24457

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 21, 2025
CWE ID 532

Summary

CVE-2025-24457 is a vulnerability affecting JetBrains YouTrack versions prior to 2024.3.55417. This issue allows permanent tokens to be exposed in logs, potentially leading to unauthorized access and data breaches. Attackers could gain access to sensitive information and perform malicious actions, such as modifying or deleting data, under the privileges of affected users. It is recommended that users of the affected software upgrade to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • JetBrains YouTrack

Affected Vendors

  • JetBrains