Insufficient Access Control in JetBrains Hub Leads to Service Hijacking
CVE-2022-34894

3.5LOW

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
1 July 2022

Summary

In JetBrains Hub prior to version 2022.2.14799, a flaw in access control mechanisms allowed unauthorized users to hijack untrusted services. This vulnerability poses a significant risk to the integrity and confidentiality of the system, potentially allowing attackers to manipulate services and disrupt operations. Affected users should upgrade to the latest version to mitigate this risk.

Affected Version(s)

Hub 2022.2.14799

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yurii Sanin
.