First published: Mon Sep 16 2024(Updated: )
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible
Credit: cve@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
IntelliJ IDEA | <2024.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46970 has a moderate severity level due to the potential for HTML injection through the project name in JetBrains IntelliJ IDEA.
To resolve CVE-2024-46970, update JetBrains IntelliJ IDEA to version 2024.1 or later.
CVE-2024-46970 affects all versions of JetBrains IntelliJ IDEA prior to 2024.1.0.
CVE-2024-46970 is classified as an HTML injection vulnerability.
CVE-2024-46970 may lead to exploitation if an attacker can manipulate the project name in a way that injects malicious HTML.