News

YouTrack update regarding Log4j2 vulnerability

Update from December 29, 2021, 16:00 (GMT +0).  The latest YouTrack and Hub versions (2021.4.36872 and 2021.1.14127 respectively) released on December 21st include log4j 2.17. To the best of our knowledge, these YouTrack and Hub versions are not affected by any known log4j-related vulnerabilities discovered to date (CVE-2021-44228, CVE-2021-45046, CVE-2021-44832 and CVE-2021-45105). Feel free to download and install these YouTrack and Hub versions.
We will no longer be updating this blog post. Any new information relating to the log4j CVEs will be published in our quarterly security bulletin. You can subscribe to the security bulletin here.

Update from December 21, 2021, 23:00 (GMT +0).  To the best of our knowledge, the newly discovered CVE-2021-45105 does not affect YouTrack or Hub.
To address another vulnerability, CVE-2021-45046, we released YouTrack 2021.4.36179 and Hub 2021.1.14108 on December 16, 2021. Please download and install these YouTrack and Hub versions. Follow the issue for more details.


Update from December 15, 2021, 21:00 (GMT +0).  We’ve found a workaround solution that lets customers without upgrade subscriptions secure their installations. Please refer to the section Securing YouTrack and Hub without upgrading below for details.
For further updates and community discussion on the topic, please follow this issue.


This announcement is about a security vulnerability that was found in a third-party library used in JetBrains YouTrack. 

YouTrack InCloud customers are already safe. We have analyzed access logs and found that no attempts were made to exploit the vulnerability before we eliminated it from YouTrack InCloud.

Administrators of some YouTrack Standalone installations must take further action to secure their instances.

Please read this announcement for a full update on the current situation and immediate action that you must take if you run a YouTrack Standalone installation.


What happened

On December 9, 2021, a security vulnerability was found in a third-party library used in JetBrains YouTrack. This security vulnerability affects YouTrack instances from version 2018.1 to version 2021.4.35732. To secure your YouTrack Standalone installation, please proceed with the steps below.

Actions for YouTrack Standalone administrators

On Friday, December 10, 2021, we sent an email to administrators of all potentially affected YouTrack Standalone instances. The email contained instructions to restart YouTrack using a parameter to disable the affected library.

It has since come to our attention that this action alone may not have been sufficient to secure some instances.

If you use YouTrack Standalone 2017.4 or earlier, you do not need to take any further action.

If you use YouTrack Standalone 2018.1 or later, please take the additional steps below to secure your YouTrack.

What actions you should take

  • If you use YouTrack Standalone 2017.4 or earlier or 2021.4.35970 or later, your installation is already safe and no additional actions are required from your side.

  • If you use YouTrack Standalone from 2018.1 to 2021.4.35732 and you have an external Hub installed, please secure your installation immediately by: 
    • upgrading YouTrack to version 2021.4.35970, and
    • upgrading Hub to version 2021.1.14080.  

      Alternatively, you can:
    • restart your YouTrack with the parameter `-Dlog4j2.formatMsgNoLookups=true`. A guide on how to apply a parameter to YouTrack can be found here (an example for Docker can be found here), and
    • restart your Hub with the parameter `-Dlog4j2.formatMsgNoLookups=true`. A guide on how to apply a parameter to Hub can be found here (an example for Docker can be found here).

      Please refer to the corresponding Hub vulnerability announcement for further details on securing your Hub installation.

  • If you use a YouTrack Standalone version from 2018.1 to 2021.2 without an external Hub, the optimal way to secure your installation is to upgrade to the latest YouTrack version 2021.4.35970

    If your upgrade subscription covers an upgrade to at least 2021.3, you can
    • upgrade to version 2021.3, and
    • restart your YouTrack with the parameter `-Dlog4j2.formatMsgNoLookups=true`. A guide on how to apply a parameter to YouTrack can be found here (an example for Docker can be found here).

  • If you use a YouTrack Standalone version from 2021.3 to 2021.4.35732 without an external Hub, please secure your installation immediately by: 
    • upgrading YouTrack to version 2021.4.35970

      Alternatively, you can:
    • restart your YouTrack with the parameter `-Dlog4j2.formatMsgNoLookups=true`. A guide on how to apply a parameter to YouTrack can be found here (an example for Docker can be found here).

Update from December 15, 2021, 21:00 (GMT +0).

End of update.

What actions we’ve taken

  • We immediately took all necessary steps to secure YouTrack InCloud instances on December 10, 2021, and applied a permanent fix to protect against the vulnerability. This required unscheduled maintenance downtime that may have coincided with your business hours and interrupted your work. We apologize for any inconvenience caused. In such situations, your security is our first priority.

  • We released a security update for YouTrack (version 2021.4.35970) on December 14, 2021. Download it here and install it.
  • We released a security update for Hub (version 2021.1.14080) on December 13, 2021. Download it here and install it.   

If you need any further assistance, please contact our support or simply comment on this blog post.

Your JetBrains YouTrack team