First published: Fri Aug 06 2021(Updated: )
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Hub | <2021.1.13389 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36209 is a vulnerability in JetBrains Hub before 2021.1.13389 that allows for account takeover during password reset.
CVE-2021-36209 has a severity rating of 9.8 out of 10, making it critical.
JetBrains Hub versions up to and excluding 2021.1.13389 are affected by CVE-2021-36209.
To fix CVE-2021-36209, update JetBrains Hub to version 2021.1.13389 or later.
More information about CVE-2021-36209 can be found in the JetBrains Security Bulletin for Q2 2021.