5
CVSSv2

CVE-2022-34894

Published: 01/07/2022 Updated: 11/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In JetBrains Hub prior to 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jetbrains hub

Github Repositories

PoC for CVE-2022-25260: pre-auth semi-blind SSRF in JetBrains Hub

CVE-2022-25260 JetBrains Hub pre-auth semi-blind server-side request forgery (SSRF) Requirements JetBrains Hub <2021114276 JetBrains Hub before 2021114276 was vulneable to improper access control (CVE-2022-34894), which allows an attacker create untrusted services without authentication even if guest user is disabled This makes it possible to exploit the vulnerabli