Local Code Execution Vulnerability in JetBrains IntelliJ IDEA
CVE-2022-29819

6.9MEDIUM

Key Information:

Vendor
Jetbrains
Vendor
CVE Published:
28 April 2022

Summary

A vulnerability in JetBrains IntelliJ IDEA allows for local code execution via links in the Quick Documentation feature. This flaw affects users of IntelliJ IDEA versions before 2022.1, enabling potential attackers to execute arbitrary code on the targeted systems. Users are recommended to update to the latest version to mitigate this risk.

Affected Version(s)

IntelliJ IDEA 2022.1

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.