PT-2019-19423 · Spring+1 · Spring Boot+1

Published

2019-07-03

·

Updated

2021-07-21

·

CVE-2019-9186

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains IntelliJ IDEA versions prior to 2019.1 JetBrains IntelliJ IDEA versions prior to 2018.3.4 JetBrains IntelliJ IDEA versions prior to 2018.2.8 JetBrains IntelliJ IDEA versions prior to 2018.1.8 JetBrains IntelliJ IDEA versions prior to 2017.3.7
Description The issue allows remote attackers to execute code when a Spring Boot run configuration is running with default settings, because a JMX server listens on all interfaces instead of only the localhost interface.
Recommendations For versions prior to 2019.1, update to version 2019.1 or later. For versions prior to 2018.3.4, update to version 2018.3.4 or later. For versions prior to 2018.2.8, update to version 2018.2.8 or later. For versions prior to 2018.1.8, update to version 2018.1.8 or later. For versions prior to 2017.3.7, update to version 2017.3.7 or later.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9186

Affected Products

Intellij Idea
Spring Boot