Vulnerabilities
Vulnerable Software
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
CVSS Score
4.5
EPSS Score
0.0
Published
2023-03-29
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
CVSS Score
4.7
EPSS Score
0.0
Published
2022-12-22
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
CVSS Score
5.0
EPSS Score
0.0
Published
2022-12-22
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.
CVSS Score
6.2
EPSS Score
0.0
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVSS Score
3.9
EPSS Score
0.0
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVSS Score
5.2
EPSS Score
0.0
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
CVSS Score
5.6
EPSS Score
0.0
Published
2022-12-08
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-12-08
The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking
CVSS Score
7.5
EPSS Score
0.0
Published
2022-09-19
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
CVSS Score
3.9
EPSS Score
0.0
Published
2022-07-28


Contact Us

Shodan ® - All rights reserved