Описание
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| intellij-idea | itp | package |
EPSS
Процентиль: 0%
0.00002
Низкий
Связанные уязвимости
CVSS3: 3.9
nvd
около 3 лет назад
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
CVSS3: 5.5
github
около 3 лет назад
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
EPSS
Процентиль: 0%
0.00002
Низкий