CVE-2019-9823: Critical severity intellij idea vulnerability
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9823?
CVE-2019-9823 is a vulnerability in several JetBrains IntelliJ IDEA versions that allows an attacker to access cleartext server credentials saved in the IDE configuration files.
How severe is CVE-2019-9823?
CVE-2019-9823 has a severity rating of 9.8, which is considered critical.
Which versions of JetBrains IntelliJ IDEA are affected by CVE-2019-9823?
JetBrains IntelliJ IDEA versions 2018.1 to 2018.1.8, 2018.2 to 2018.2.8, and 2018.3 to 2018.3.5 are affected by CVE-2019-9823.
How can I fix CVE-2019-9823?
To fix CVE-2019-9823, update your JetBrains IntelliJ IDEA to version 2018.3.5, 2018.2.8, or 2018.1.8.
Where can I find more information about CVE-2019-9823?
You can find more information about CVE-2019-9823 in the JetBrains Security Bulletin Q1 2019: https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/