Two-Factor Authentication Settings Vulnerability in JetBrains Hub
CVE-2021-25759

6.5MEDIUM

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
3 February 2021

Summary

In JetBrains Hub versions prior to 2020.1.12629, an authenticated user has the ability to delete two-factor authentication (2FA) settings for any other user. This vulnerability poses a significant risk as it can compromise user accounts and bypass security controls designed to protect sensitive data. Proper access controls should be instituted to prevent unauthorized users from manipulating 2FA configurations.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.