CVE-2020-7906: High severity JetBrains Rider vulnerability
In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains Riderto a version that resolves this vulnerability.Fixed in 2019.3
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7906?
CVE-2020-7906 has a medium severity rating due to the presence of unsigned binaries in the affected versions.
How do I fix CVE-2020-7906?
To fix CVE-2020-7906, upgrade to JetBrains Rider version 2019.3 or later.
Which versions of JetBrains Rider are affected by CVE-2020-7906?
CVE-2020-7906 affects JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7.
What are the risks associated with CVE-2020-7906?
The risks associated with CVE-2020-7906 include potential exploitation due to unsigned binaries which may lead to security breaches.
Is there a public disclosure for CVE-2020-7906?
Yes, CVE-2020-7906 was publicly disclosed by JetBrains in a security bulletin.