Vulnerability Details CVE-2019-14957
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.1%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2019-14957
-
cpe:2.3:a:jetbrains:vim:-
-
cpe:2.3:a:jetbrains:vim:0.46
-
cpe:2.3:a:jetbrains:vim:0.47
-
cpe:2.3:a:jetbrains:vim:0.48
-
cpe:2.3:a:jetbrains:vim:0.49
-
cpe:2.3:a:jetbrains:vim:0.50
-
cpe:2.3:a:jetbrains:vim:0.51