CVE-2019-14957: Medium severity jetbrains vim vulnerability
Published Oct 1, 2019
·Updated
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vimsettings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
Affected Software
1 affected component
JetBrains Vim<0.52
Event History
Oct 1, 2019
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14957?
CVE-2019-14957 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-14957?
To fix CVE-2019-14957, upgrade the JetBrains Vim plugin to version 0.52 or later.
3
What does CVE-2019-14957 affect?
CVE-2019-14957 affects the JetBrains Vim plugin versions before 0.52.
4
What risk does CVE-2019-14957 pose to users?
CVE-2019-14957 can expose individual project data if the global vim_settings.xml file is synced to a public GitHub repository.
5
When was CVE-2019-14957 disclosed?
CVE-2019-14957 was disclosed in September 2019.