9.1
CVSSv3

CVE-2022-25260

Published: 25/02/2022 Updated: 08/03/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

JetBrains Hub prior to 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jetbrains hub

Github Repositories

PoC for CVE-2022-25260: pre-auth semi-blind SSRF in JetBrains Hub

CVE-2022-25260 JetBrains Hub pre-auth semi-blind server-side request forgery (SSRF) Requirements JetBrains Hub <2021114276 JetBrains Hub before 2021114276 was vulneable to improper access control (CVE-2022-34894), which allows an attacker create untrusted services without authentication even if guest user is disabled This makes it possible to exploit the vulnerabli