CVE-2019-9873: Critical severity intellij idea vulnerability
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-9873.
What is the severity of CVE-2019-9873?
CVE-2019-9873 has a severity rating of 9.8 (Critical).
How does this vulnerability occur?
This vulnerability occurs when creating Task Servers configurations in several versions of JetBrains IntelliJ IDEA Ultimate.
What is the impact of CVE-2019-9873?
The impact of CVE-2019-9873 is the saving of a cleartext unencrypted record of server credentials in the IDE configuration files.
Which versions of JetBrains IntelliJ IDEA Ultimate are affected?
The affected versions of JetBrains IntelliJ IDEA Ultimate include 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.
How can I fix this vulnerability?
To fix this vulnerability, update to the fixed versions of JetBrains IntelliJ IDEA Ultimate: 2019.1, 2018.3.5, 2018.2.8, or 2018.1.8.