QID 375432

Date Published: 2021-04-07

QID 375432: JetBrains Intellij IDEA Potentially Insecure Deserialization Vulnerability (IDEA-253582)

IntelliJ IDEA is an integrated development environment written in Java for developing computer software

Affected Versions:
Before 2020.3.0.0

QID Detection Logic(Authenticated)
This QID detects the vulnerable version by checking the JetBrains Intellij IDEA.exe file version.

Potentially insecure deserialization of the workspace model could lead to local code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to JetBrains advisory IDEA-253582 for affected packages and patching details.

    CVEs related to QID 375432

    Software Advisories
    Advisory ID Software Component Link
    IDEA-253582 URL Logo blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/