Improper preservation of permissions in YouTrack - CVE-2019-14956

 

Improper preservation of permissions in YouTrack - CVE-2019-14956

Published: November 4, 2019


Vulnerability identifier: #VU22491
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14956
CWE-ID:
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain sensitive information on the target system.

The vulnerability exists due to the affected software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects. A remote authenticated user without necessary permissions can get a list of project names.

Affected software

YouTrack

How to mitigate CVE-2019-14956

Install updates from vendor's website.

YouTrack - update to 2019.2.53938

External References

Related Security Bulletins