Vulnerabilities > Jetbrains > HUB

DATE CVE VULNERABILITY TITLE RISK
2022-02-25 CVE-2022-24327 Incorrect Permission Assignment for Critical Resource vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
network
low complexity
jetbrains CWE-732
7.5
2022-02-25 CVE-2022-24328 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
network
low complexity
jetbrains
6.5
2021-11-09 CVE-2021-43180 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
network
low complexity
jetbrains
7.5
2021-11-09 CVE-2021-43181 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
network
low complexity
jetbrains CWE-79
6.1
2021-11-09 CVE-2021-43182 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
network
low complexity
jetbrains
7.5
2021-11-09 CVE-2021-43183 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
network
low complexity
jetbrains
critical
9.8
2021-08-06 CVE-2021-36209 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
network
low complexity
jetbrains CWE-640
critical
9.8
2021-08-06 CVE-2021-37540 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
network
low complexity
jetbrains
6.5
2021-08-06 CVE-2021-37541 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
network
low complexity
jetbrains CWE-640
6.1
2021-05-11 CVE-2021-31901 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
network
low complexity
jetbrains
7.5