PT-2022-27984 · Jetbrains · Intellij Idea

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-46827

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JetBrains IntelliJ IDEA versions prior to 2022.3
Description The issue allows for an XXE attack, which can lead to a Server-Side Request Forgery (SSRF) via requests to custom plugin repositories. This occurs due to a flaw in handling requests to these repositories, enabling an attacker to potentially exploit the system.
Recommendations For versions prior to 2022.3, update to version 2022.3 or later to resolve the issue. As a temporary workaround, consider restricting access to custom plugin repositories until the update is applied.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-46827

Affected Products

Intellij Idea