PT-2024-6311 · Jetbrains · Jetbrains Intellij Idea
Published
2024-09-16
·
Updated
2024-09-20
·
CVE-2024-46970
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JetBrains IntelliJ IDEA versions prior to 2024.1
Description
The issue is related to the lack of protection of the web page structure in the integrated development environment, allowing for HTML injection via the project name. This could enable an attacker to implement cross-site scripting attacks, potentially leading to malicious script injection.
Recommendations
For versions prior to 2024.1, upgrade the affected component to the latest version to patch the issue. As a temporary workaround, consider restricting the use of project names to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetbrains Intellij Idea