CVE Vulnerabilities

CVE-2022-48477

Server-Side Request Forgery (SSRF)

Published: Apr 24, 2023 | Modified: May 02, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Hub Jetbrains * 2023.1.15725 (excluding)

References