CVE-2025-24456
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Jan 21, 2025
CWE ID 288
Summary
CVE-2025-24456 is a privilege escalation vulnerability affecting JetBrains Hub before version 2024.3.55417. Maliciously crafted LDAP authentication mappings could be exploited to elevate user privileges, potentially granting unauthorized access to sensitive information or system functions within the Hub environment. This issue poses a significant risk to organizations using JetBrains Hub and emphasizes the importance of applying the latest security patches to mitigate potential threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- JetBrains Hub
Affected Vendors
- JetBrains