CVE-2019-9823: JetBrains Intellij Idea

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.

Affected products

  • JetBrains Intellij Idea: from 2018.1, before 2018.1.8 (fixed in 2018.1.8); from 2018.2, before 2018.2.8 (fixed in 2018.2.8); from 2018.3, before 2018.3.5 (fixed in 2018.3.5)

Published 2019-07-03. Last modified 2026-06-17.