Vulnerabilities > Jetbrains > HUB > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-28 CVE-2024-50573 Missing Authorization vulnerability in Jetbrains HUB
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
network
low complexity
jetbrains CWE-862
5.4
2024-06-18 CVE-2024-38507 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
network
low complexity
jetbrains CWE-79
5.4
2023-03-27 CVE-2022-48429 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
network
low complexity
jetbrains CWE-79
5.4
2022-07-01 CVE-2022-34894 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
network
low complexity
jetbrains
5.3
2022-04-28 CVE-2022-29811 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
network
low complexity
jetbrains CWE-79
4.8
2022-02-25 CVE-2022-25259 Cross-site Scripting vulnerability in Jetbrains HUB
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
network
low complexity
jetbrains CWE-79
6.1
2022-02-25 CVE-2022-24328 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
network
low complexity
jetbrains
6.5
2021-11-09 CVE-2021-43181 Cross-site Scripting vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
network
low complexity
jetbrains CWE-79
6.1
2021-08-06 CVE-2021-37540 Unspecified vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
network
low complexity
jetbrains
6.5
2021-08-06 CVE-2021-37541 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
network
low complexity
jetbrains CWE-640
6.1