CVE-2019-12847: JetBrains Hub

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

Affected products

  • JetBrains Hub: before 2018.4.11298 (fixed in 2018.4.11298)

Published 2019-07-03. Last modified 2026-06-17.