PT-2019-19423 · Spring+1 · Spring Boot+1
Published
2019-07-03
·
Updated
2021-07-21
·
CVE-2019-9186
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains IntelliJ IDEA versions prior to 2019.1
JetBrains IntelliJ IDEA versions prior to 2018.3.4
JetBrains IntelliJ IDEA versions prior to 2018.2.8
JetBrains IntelliJ IDEA versions prior to 2018.1.8
JetBrains IntelliJ IDEA versions prior to 2017.3.7
Description
The issue allows remote attackers to execute code when a Spring Boot run configuration is running with default settings, because a JMX server listens on all interfaces instead of only the localhost interface.
Recommendations
For versions prior to 2019.1, update to version 2019.1 or later.
For versions prior to 2018.3.4, update to version 2018.3.4 or later.
For versions prior to 2018.2.8, update to version 2018.2.8 or later.
For versions prior to 2018.1.8, update to version 2018.1.8 or later.
For versions prior to 2017.3.7, update to version 2017.3.7 or later.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intellij Idea
Spring Boot