CVE-2019-9186: Critical severity intellij idea vulnerability
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-9186.
What is the severity of CVE-2019-9186?
The severity of CVE-2019-9186 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2019-9186?
JetBrains IntelliJ IDEA versions between 2018.1 and 2019.1 are affected.
How can remote attackers exploit CVE-2019-9186?
Remote attackers can exploit CVE-2019-9186 by executing code when a Spring Boot run configuration is running in the affected JetBrains IntelliJ IDEA versions.
Is there a fix available for CVE-2019-9186?
Yes, JetBrains has released a security update to address the vulnerability. It is recommended to update to the latest version of JetBrains IntelliJ IDEA.