CVE-2019-14955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
01/10/2019
Last modified:
08/10/2019

Description

In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jetbrains:hub:*:*:*:*:*:*:*:* 2018.4.11436 (excluding)