Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3h7w-w4qf-f3pr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

EPSS

Процентиль: 0%
0.00003
Низкий

7.2 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 7.2
nvd
больше 6 лет назад

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

EPSS

Процентиль: 0%
0.00003
Низкий

7.2 High

CVSS3

Дефекты

CWE-522