CVE Vulnerabilities

CVE-2025-24456

Authentication Bypass Using an Alternate Path or Channel

Published: Jan 21, 2025 | Modified: Jan 30, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
HubJetbrains*2024.3.55417 (excluding)

Potential Mitigations

References