PT-2019-19423 · Spring+1 · Spring Boot+1

Publicado

2019-07-03

·

Atualizado

2021-07-21

·

CVE-2019-9186

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains IntelliJ IDEA versions prior to 2019.1 JetBrains IntelliJ IDEA versions prior to 2018.3.4 JetBrains IntelliJ IDEA versions prior to 2018.2.8 JetBrains IntelliJ IDEA versions prior to 2018.1.8 JetBrains IntelliJ IDEA versions prior to 2017.3.7
Description The issue allows remote attackers to execute code when a Spring Boot run configuration is running with default settings, because a JMX server listens on all interfaces instead of only the localhost interface.
Recommendations For versions prior to 2019.1, update to version 2019.1 or later. For versions prior to 2018.3.4, update to version 2018.3.4 or later. For versions prior to 2018.2.8, update to version 2018.2.8 or later. For versions prior to 2018.1.8, update to version 2018.1.8 or later. For versions prior to 2017.3.7, update to version 2017.3.7 or later.

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9186

Produtos afetados

Intellij Idea
Spring Boot