CVE-2020-7914

HIGH

JetBrains IntelliJ IDEA <2019.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

In JetBrains IntelliJ IDEA 2019.2, an XSLT debugger plugin misconfiguration allows arbitrary file read operations over the network. This issue was fixed in 2019.3.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://blog.jetbrains.com

Scores

CVSS v3 7.5
EPSS 0.0000
EPSS Percentile 0.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
jetbrains/intellij_idea < 2019.3.0
Published Jan 31, 2020
Tracked Since Feb 18, 2026