First published: Thu Dec 22 2022(Updated: )
In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JAR files.
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains IntelliJ IDEA | <2022.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-47895.
The affected software is JetBrains IntelliJ IDEA before version 2022.3.1.
The severity of CVE-2022-47895 is high with a CVSS score of 7.5.
The CWE category of this vulnerability is CWE-319.
To fix CVE-2022-47895, update JetBrains IntelliJ IDEA to version 2022.3.1 or higher.