CVE-2022-25260
CRITICALJetBrains Hub < 2021.1.14276 - Server-Side Request Forgery
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-25260. PoCs published by yuriisanin.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-25260, a pre-auth semi-blind SSRF vulnerability in JetBrains Hub. The exploit leverages improper access control (CVE-2022-34894) to create untrusted services and uses SVG rasterization to trigger SSRF requests.
Description
JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
Exploits (1)
This repository contains a functional exploit for CVE-2022-25260, a pre-auth semi-blind SSRF vulnerability in JetBrains Hub. The exploit leverages improper access control (CVE-2022-34894) to create untrusted services and uses SVG rasterization to trigger SSRF requests.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N