Jetbrains
Jetbrains HUB: vulnerabilidades y CVE
Jetbrains HUB tiene 38 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE38
Últimos 12 meses10
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100266 | Alta (7.7) | 0.30% | — | 30 sept 2026 | In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address |
| CVE-2026-86480 | Crítica (9.8) | 0.50% | — | 7 sept 2026 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
| CVE-2026-56142 | Alta (8.8) | 0.62% | — | 19 jun 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible |
| CVE-2026-56141 | Crítica (9.8) | 0.52% | — | 19 jun 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible |
| CVE-2026-50242 | Crítica (9.8) | 0.61% | — | 19 jun 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible |
| CVE-2026-32229 | Media (6.8) | 0.28% | — | 11 mar 2026 | In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled |
| CVE-2026-25848 | Crítica (9.8) | 0.60% | — | 9 feb 2026 | In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible |
| CVE-2025-64683 | Alta (7.5) | 0.20% | — | 10 nov 2025 | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API |
| CVE-2025-64682 | Baja (3.7) | 0.16% | — | 10 nov 2025 | In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit |
| CVE-2025-64681 | Baja (3.7) | 0.19% | — | 10 nov 2025 | In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations |
| CVE-2025-24456 | Alta (8.8) | 0.29% | — | 21 ene 2025 | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping |
| CVE-2024-50573 | Media (5.4) | 0.22% | — | 28 oct 2024 | In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services |
| CVE-2024-38507 | Media (5.4) | 0.24% | — | 18 jun 2024 | In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible |
| CVE-2022-48477 | Crítica (9.8) | 0.48% | — | 24 abr 2023 | In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing |
| CVE-2022-48429 | Media (5.4) | 0.60% | — | 27 mar 2023 | In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible |
| CVE-2022-45471 | Alta (7.5) | 0.55% | — | 18 nov 2022 | In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address |
| CVE-2022-34894 | Media (5.3) | 0.59% | — | 1 jul 2022 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services |
| CVE-2022-29811 | Media (4.8) | 0.48% | — | 28 abr 2022 | In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. |
| CVE-2022-25262 | Crítica (9.8) | 1.4% | — | 25 feb 2022 | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. |
| CVE-2022-25260 | Crítica (9.1) | 2.4% | — | 25 feb 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). |
| CVE-2022-25259 | Media (6.1) | 0.57% | — | 25 feb 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS. |
| CVE-2022-24328 | Media (6.5) | 0.82% | — | 25 feb 2022 | In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. |
| CVE-2022-24327 | Alta (7.5) | 0.91% | — | 25 feb 2022 | In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. |
| CVE-2021-43182 | Alta (7.5) | 0.96% | — | 9 nov 2021 | In JetBrains Hub before 2021.1.13415, a DoS via user information is possible. |
| CVE-2021-43181 | Media (6.1) | 0.58% | — | 9 nov 2021 | In JetBrains Hub before 2021.1.13690, stored XSS is possible. |
| CVE-2021-43180 | Alta (7.5) | 1.0% | — | 9 nov 2021 | In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible. |
| CVE-2021-43183 | Crítica (9.8) | 1.2% | — | 9 nov 2021 | In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed. |
| CVE-2021-37541 | Media (6.1) | 0.55% | — | 6 ago 2021 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. |
| CVE-2021-37540 | Media (6.5) | 0.66% | — | 6 ago 2021 | In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. |
| CVE-2021-36209 | Crítica (9.8) | 1.0% | — | 6 ago 2021 | In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.