API Method Vulnerability in JetBrains IntelliJ IDEA Web Server
CVE-2022-48433

6.1MEDIUM

Key Information:

Vendor
Jetbrains
Vendor
CVE Published:
29 March 2023

Summary

A security vulnerability exists in JetBrains IntelliJ IDEA prior to the 2023.1 release that allows for the potential leakage of NTLM hashes through an API method utilized by the built-in web server. This issue raises significant concerns regarding user credential protection and server-side security, highlighting the need for timely software updates to mitigate risks associated with unauthorized access.

Affected Version(s)

IntelliJ IDEA Windows 0 < 2023.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.