In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://blog.jetbrains.com | vendor advisory |
https://www.jetbrains.com/privacy-security/issues-fixed/ | vendor advisory |