CVE Vulnerabilities

CVE-2025-24456

Authentication Bypass Using an Alternate Path or Channel

Published: Jan 21, 2025 | Modified: Jan 30, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

Name Vendor Start Version End Version
Hub Jetbrains * 2024.3.55417 (excluding)

Potential Mitigations

References