Project Import Vulnerability in JetBrains IntelliJ IDEA
CVE-2022-48431

4.5MEDIUM

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
29 March 2023

What is CVE-2022-48431?

In JetBrains IntelliJ IDEA prior to version 2023.1, a vulnerability exists that may allow Gradle and Maven projects to be imported without the necessary user verification step of confirming the ā€˜Trust Project’ dialog. This omission poses potential security risks, as it might enable malicious projects to be executed inadvertently, compromising the integrity of the development environment.

Affected Version(s)

IntelliJ IDEA 0 < 2023.1

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.