CVE-2019-12847: High severity jetbrains hub vulnerability
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12847?
The severity of CVE-2019-12847 is high with a severity value of 7.2.
What is the vulnerability in JetBrains Hub versions earlier than 2018.4.11298?
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user.
What is the impact of CVE-2019-12847?
The impact of CVE-2019-12847 is that the audit events for SMTPSettings may reveal a cleartext password to the admin user.
How can I determine if my version of JetBrains Hub is affected?
If your version of JetBrains Hub is earlier than 2018.4.11298, it is affected by CVE-2019-12847.
How can I mitigate the vulnerability in JetBrains Hub versions earlier than 2018.4.11298?
To mitigate the vulnerability, update JetBrains Hub to version 2018.4.11298 or later.