Local Code Execution Vulnerability in JetBrains IntelliJ IDEA
CVE-2022-37009

3.9LOW

Key Information:

Vendor
Jetbrains
Vendor
CVE Published:
28 July 2022

Summary

A vulnerability in JetBrains IntelliJ IDEA allows for local code execution through a Vagrant executable. This flaw can be exploited by an attacker who can manipulate the Vagrant environment, potentially leading to unauthorized execution of commands on the host machine. Users of versions 2022.1 and earlier should take caution and apply security measures promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

IntelliJ IDEA 2022.2

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.