PT-2022-3565 · Jetbrains · Jetbrains Hub

Published

2022-02-25

·

Updated

2023-08-08

·

CVE-2022-25262

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains Hub versions prior to 2022.1.14434
Description The issue is related to insufficient authentication data verification in JetBrains Hub, allowing a remote attacker to exploit the vulnerability and gain access to confidential data, compromise its integrity, and cause a denial of service. The vulnerability is associated with SAML request takeover.
Recommendations For versions prior to 2022.1.14434, update to version 2022.1.14434 or later to resolve the issue. As a temporary workaround, consider restricting access to SAML authentication to minimize the risk of exploitation.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-04349
CVE-2022-25262

Affected Products

Jetbrains Hub