PT-2022-3565 · Jetbrains · Jetbrains Hub
Published
2022-02-25
·
Updated
2023-08-08
·
CVE-2022-25262
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains Hub versions prior to 2022.1.14434
Description
The issue is related to insufficient authentication data verification in JetBrains Hub, allowing a remote attacker to exploit the vulnerability and gain access to confidential data, compromise its integrity, and cause a denial of service. The vulnerability is associated with SAML request takeover.
Recommendations
For versions prior to 2022.1.14434, update to version 2022.1.14434 or later to resolve the issue. As a temporary workaround, consider restricting access to SAML authentication to minimize the risk of exploitation.
Exploit
Fix
Insufficient Verification of Data Authenticity
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetbrains Hub