CVE-2022-29813: Code Injection
Published Apr 28, 2022
·Updated
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2022.1
Event History
Apr 28, 2022
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-29813?
CVE-2022-29813 is a vulnerability in JetBrains IntelliJ IDEA before 2022.1 that allows local code execution via a custom Pandoc path.
2
How severe is CVE-2022-29813?
CVE-2022-29813 has a severity level of medium with a CVSS score of 6.7.
3
How can the vulnerability CVE-2022-29813 be exploited?
CVE-2022-29813 can be exploited by an attacker with local access to the affected system, who can set a custom Pandoc path to execute code.
4
Is JetBrains IntelliJ IDEA version 2022.1 affected by CVE-2022-29813?
Yes, JetBrains IntelliJ IDEA version 2022.1 is affected by CVE-2022-29813.
5
How can I fix the vulnerability CVE-2022-29813 in JetBrains IntelliJ IDEA?
To fix the vulnerability CVE-2022-29813 in JetBrains IntelliJ IDEA, update to a version later than 2022.1 or apply the necessary patches provided by JetBrains.