PT-2026-25323 · Jetbrains · Jetbrains Datalore
Published
2026-03-13
·
Updated
2026-03-14
·
CVE-2026-32745
CVSS v2.0
6.8
Medium
| Vector | AV:A/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JetBrains Datalore versions prior to 2026.1
Description
A session hijacking issue existed in JetBrains Datalore due to the absence of the secure attribute for cookie settings. This allowed for potential unauthorized access to user sessions.
Recommendations
Update JetBrains Datalore to version 2026.1 or later.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jetbrains Datalore