PT-2022-27985 · Jetbrains · Jetbrains Intellij Idea

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-46828

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains IntelliJ IDEA versions prior to 2022.3
Description The issue allows for a DYLIB injection on macOS. This means that an attacker could potentially inject malicious code into the system. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 2022.3, update to version 2022.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the DYLIB loading functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-46828

Affected Products

Jetbrains Intellij Idea