Local Code Execution Vulnerability in JetBrains IntelliJ IDEA
CVE-2022-37009
3.9LOW
Summary
A vulnerability in JetBrains IntelliJ IDEA allows for local code execution through a Vagrant executable. This flaw can be exploited by an attacker who can manipulate the Vagrant environment, potentially leading to unauthorized execution of commands on the host machine. Users of versions 2022.1 and earlier should take caution and apply security measures promptly to mitigate risks associated with this vulnerability.
Affected Version(s)
IntelliJ IDEA 2022.2
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved