PT-2019-19423 · Spring+1 · Spring Boot+1
Publicado
2019-07-03
·
Atualizado
2021-07-21
·
CVE-2019-9186
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains IntelliJ IDEA versions prior to 2019.1
JetBrains IntelliJ IDEA versions prior to 2018.3.4
JetBrains IntelliJ IDEA versions prior to 2018.2.8
JetBrains IntelliJ IDEA versions prior to 2018.1.8
JetBrains IntelliJ IDEA versions prior to 2017.3.7
Description
The issue allows remote attackers to execute code when a Spring Boot run configuration is running with default settings, because a JMX server listens on all interfaces instead of only the localhost interface.
Recommendations
For versions prior to 2019.1, update to version 2019.1 or later.
For versions prior to 2018.3.4, update to version 2018.3.4 or later.
For versions prior to 2018.2.8, update to version 2018.2.8 or later.
For versions prior to 2018.1.8, update to version 2018.1.8 or later.
For versions prior to 2017.3.7, update to version 2017.3.7 or later.
Correção
Exposure of Resource to Wrong Sphere
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Intellij Idea
Spring Boot