Information Disclosure in JetBrains Hub Affected by Users API
CVE-2025-64683

5.3MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
10 November 2025

What is CVE-2025-64683?

An information disclosure vulnerability exists in JetBrains Hub prior to version 2025.3.104432, which allows unauthorized access to sensitive information via the Users API. This vulnerability could enable malicious actors to reveal user details, posing significant risks to data privacy and security. Organizations using affected versions should prioritize patching to safeguard against potential unauthorized data exposure.

Affected Version(s)

Hub 0 < 2025.3.104432

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.