CVE-2025-53959
BaseFortify
Publication date: 2025-07-15
Last updated on: 2025-10-14
Assigner: JetBrains s.r.o.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jetbrains | youtrack | to 2024.3.85077 (exc) |
| jetbrains | youtrack | From 2025.1.62455 (inc) to 2025.1.86199 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in JetBrains YouTrack versions before 2025.2.86069, 2024.3.85077, and 2025.1.86199 allows email spoofing via an administrative API. This means an attacker with some level of privileges could send emails that appear to come from a trusted source within the system.
How can this vulnerability impact me? :
The vulnerability can lead to email spoofing, which may result in phishing attacks, misinformation, or unauthorized communication appearing to come from legitimate administrative sources. This can undermine trust, lead to data leaks, or facilitate further attacks.