Inclusion of Sensitive Information in Log Files in YouTrack - CVE-2025-24457
Published: January 21, 2025 / Updated: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in token parsing when processing a malformed permanent token that cannot be parsed. A remote user can supply a malformed permanent token to expose the token in logs and disclose sensitive information.