CVE-2020-7904: High severity JetBrains IntelliJ IDEA vulnerability
Published Jan 30, 2020
·Updated
In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2019.3.0
Event History
Jan 30, 2020
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-7904.
2
What is the severity rating of CVE-2020-7904?
The severity rating of CVE-2020-7904 is high with a score of 7.4.
3
How does CVE-2020-7904 affect JetBrains IntelliJ IDEA?
CVE-2020-7904 affects JetBrains IntelliJ IDEA versions up to and excluding 2019.3.0.
4
What was the issue with Maven repositories in JetBrains IntelliJ IDEA before 2019.3?
In IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.
5
Where can I find more information about CVE-2020-7904?
You can find more information about CVE-2020-7904 in the JetBrains security bulletin for Q4 2019: https://blog.jetbrains.com/blog/2020/01/24/jetbrains-security-bulletin-q4-2019/