CVE-2019-14954: Medium severity intellij idea vulnerability
Published Oct 1, 2019
·Updated
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2019.2
Event History
Oct 1, 2019
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-14954.
2
What is the severity of CVE-2019-14954?
The severity of CVE-2019-14954 is medium (5.9).
3
How does this vulnerability affect JetBrains IntelliJ IDEA?
This vulnerability affects JetBrains IntelliJ IDEA versions prior to 2019.2.
4
What is the impact of this vulnerability?
The impact of this vulnerability is that JetBrains IntelliJ IDEA resolves the markdown plantuml artifact download link via an insecure cleartext HTTP connection.
5
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is to upgrade JetBrains IntelliJ IDEA to version 2019.2 or later.