CVE-2022-48477: SSRF
Published Apr 24, 2023
·Updated
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
Affected Software
1 affected component
JetBrains Hub<2023.1.15725
Event History
Apr 24, 2023
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this SSRF protection issue in JetBrains Hub?
The vulnerability ID is CVE-2022-48477.
2
What is the severity rating for this SSRF protection issue in JetBrains Hub?
The severity rating is critical with a CVSS score of 9.8.
3
What is SSRF protection and why is it important in JetBrains Hub?
SSRF protection is the mitigation technique used to prevent Server-Side Request Forgery attacks, which can lead to unauthorized access to internal resources or sensitive data in JetBrains Hub.
4
How do I know if my version of JetBrains Hub is affected by this vulnerability?
If your version of JetBrains Hub is before 2023.1.15725, then it is affected by this SSRF protection issue.
5
How can I fix this SSRF protection issue in JetBrains Hub?
To fix this SSRF protection issue, you should update your JetBrains Hub to version 2023.1.15725 or newer, where the vulnerability has been fixed.