Information Disclosure in JetBrains Hub Affected by Users API
CVE-2025-64683
5.3MEDIUM
What is CVE-2025-64683?
An information disclosure vulnerability exists in JetBrains Hub prior to version 2025.3.104432, which allows unauthorized access to sensitive information via the Users API. This vulnerability could enable malicious actors to reveal user details, posing significant risks to data privacy and security. Organizations using affected versions should prioritize patching to safeguard against potential unauthorized data exposure.
Affected Version(s)
Hub 0 < 2025.3.104432
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved