SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

MEDIUM 5.4EPSS 0.38%

Does this matter?

Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.

Description

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS
0.38% probability · 31th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
jetbrains/youtrack
Source
cve@jetbrains.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.