CVE-2019-9872: JetBrains Intellij Idea

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.

Affected products

  • JetBrains Intellij Idea: from 2018.1, before 2018.1.8 (fixed in 2018.1.8); from 2018.2, before 2018.2.8 (fixed in 2018.2.8); from 2018.3, before 2018.3.5 (fixed in 2018.3.5); from 2018.3.6, before 2019.1 (fixed in 2019.1)

Published 2019-07-03. Last modified 2026-06-17.