Known Vulnerabilities for Intellij Idea by Jetbrains
Listed below are 10 of the newest known vulnerabilities associated with "Intellij Idea" by "Jetbrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24346 | In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible. | 7.8 - HIGH | 2022-02-25 | 2022-03-04 |
| CVE-2022-24345 | In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was ... | 7.8 - HIGH | 2022-02-25 | 2022-03-04 |
| CVE-2021-30504 | In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation. | 7.5 - HIGH | 2021-05-11 | 2021-05-14 |
| CVE-2021-30006 | In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. | 7.5 - HIGH | 2021-05-11 | 2021-05-17 |
| CVE-2021-29263 | In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the projec... | 7.8 - HIGH | 2021-05-11 | 2021-05-17 |
| CVE-2021-25758 | In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local cod... | 7.8 - HIGH | 2021-02-03 | 2021-12-10 |
| CVE-2021-25756 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. | 5.3 - MEDIUM | 2021-02-03 | 2021-02-05 |
| CVE-2020-7914 | In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the ne... | 7.5 - HIGH | 2020-01-31 | 2021-07-21 |
| CVE-2020-7905 | Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network. | 7.5 - HIGH | 2020-01-30 | 2021-07-21 |
| CVE-2020-7904 | In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS. | 7.4 - HIGH | 2020-01-30 | 2020-02-01 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Intellij Idea | 9.0.4 | All | All | All |
| Application | Jetbrains | Intellij Idea | 9.0.3 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2020.3 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2020.2 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2020.1 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.3.4 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.3.3 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.3.0 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.3 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.2.4 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.2.3 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.2.2 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.2.1 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.2 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.1.4 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.1.3 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.1.2 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.1.1 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2019.1 | All | All | All |
| Application | Jetbrains | Intellij Idea | 2018.3.6 | All | All | All |