Hub
by Jetbrains
CVEs (36)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25259 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS. | ||
| CVE-2021-43181 | Med | 0.40 | 6.1 | 0.01 | Nov 9, 2021 | In JetBrains Hub before 2021.1.13690, stored XSS is possible. | ||
| CVE-2021-37541 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2021 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. | ||
| CVE-2021-25757 | Med | 0.40 | 6.1 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an open redirect was possible. | ||
| CVE-2021-25760 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2021 | In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible. | ||
| CVE-2019-18360 | Med | 0.35 | 5.3 | 0.01 | Oct 31, 2019 | In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery. | ||
| CVE-2019-14955 | Med | 0.35 | 5.3 | 0.01 | Oct 1, 2019 | In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented. | ||
| CVE-2025-64683 | Med | 0.34 | 5.3 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API | ||
| CVE-2022-48429 | Med | 0.30 | 4.6 | 0.01 | Mar 27, 2023 | In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible | ||
| CVE-2024-50573 | Med | 0.28 | 4.3 | 0.00 | Oct 28, 2024 | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services | ||
| CVE-2022-48477 | Med | 0.27 | 4.1 | 0.00 | Apr 24, 2023 | In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing | ||
| CVE-2024-38507 | Low | 0.23 | 3.5 | 0.00 | Jun 18, 2024 | In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible | ||
| CVE-2022-45471 | Low | 0.23 | 3.5 | 0.01 | Nov 18, 2022 | In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address | ||
| CVE-2022-34894 | Low | 0.23 | 3.5 | 0.01 | Jul 1, 2022 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services | ||
| CVE-2025-64682 | Low | 0.18 | 2.7 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit | ||
| CVE-2025-64681 | Low | 0.18 | 2.7 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations |
- risk 0.40cvss 6.1epss 0.01
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- risk 0.40cvss 6.1epss 0.01
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
- risk 0.35cvss 5.3epss 0.01
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
- risk 0.34cvss 5.3epss 0.00
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
- risk 0.30cvss 4.6epss 0.01
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
- risk 0.28cvss 4.3epss 0.00
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
- risk 0.27cvss 4.1epss 0.00
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
- risk 0.23cvss 3.5epss 0.00
In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible
- risk 0.23cvss 3.5epss 0.01
In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address
- risk 0.23cvss 3.5epss 0.01
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
- risk 0.18cvss 2.7epss 0.00
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
- risk 0.18cvss 2.7epss 0.00
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
Page 2 of 2