CVE-2019-9186: JetBrains Intellij Idea
Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
Affected products
- JetBrains Intellij Idea: from 2018.1, before 2018.1.8 (fixed in 2018.1.8); from 2018.2, before 2018.2.8 (fixed in 2018.2.8); from 2018.3, before 2018.3.5 (fixed in 2018.3.5); from 2018.3.6, before 2019.1 (fixed in 2019.1)
Published 2019-07-03. Last modified 2026-06-17.