PT-2022-27984 · Jetbrains · Intellij Idea
Published
2022-12-08
·
Updated
2022-12-12
·
CVE-2022-46827
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JetBrains IntelliJ IDEA versions prior to 2022.3
Description
The issue allows for an XXE attack, which can lead to a Server-Side Request Forgery (SSRF) via requests to custom plugin repositories. This occurs due to a flaw in handling requests to these repositories, enabling an attacker to potentially exploit the system.
Recommendations
For versions prior to 2022.3, update to version 2022.3 or later to resolve the issue. As a temporary workaround, consider restricting access to custom plugin repositories until the update is applied.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intellij Idea