First published: Wed Mar 29 2023(Updated: )
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains IntelliJ IDEA | <2023.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this JetBrains IntelliJ IDEA vulnerability is CVE-2022-48433.
The title of this vulnerability is 'In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.'
The affected software for this vulnerability is JetBrains IntelliJ IDEA up to exclusive version 2023.1.
The severity of this vulnerability is high with a CVSS score of 7.5.
To fix this vulnerability, you should update JetBrains IntelliJ IDEA to version 2023.1 or a later version.