Reflected XSS Vulnerability in JetBrains IntelliJ IDEA
CVE-2022-29817
3.9LOW
Summary
A reflected XSS vulnerability exists in JetBrains IntelliJ IDEA prior to version 2022.1, enabling attackers to exploit error messages generated by the internal web server. By crafting malicious requests, an attacker could manipulate error responses to execute arbitrary scripts in the context of a user's session, compromising the security of the application. Users and administrators are recommended to review the impacted versions and apply necessary updates to mitigate potential risks.
Affected Version(s)
IntelliJ IDEA 2022.1
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved