CVE-2024-54158CWE-173

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

Low · published December 4, 2024

CVSS v3.1
3.5
EPSS
0%
Percentile
23.1
In the wild
Unconfirmed
What it is

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

The record
Technical detail
CVSS v3.1
3.5 · LOW
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00308 · 23.1th percentile
Weakness
CWE-173 · Improper Handling of Alternate Encoding
Published
2024-12-04T11:16Z
EPSS history
Timeline
  • 04 DEC 11:16Z
    In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
    cvelistv5