CVE-2019-9873: JetBrains Intellij Idea

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.

Affected products

  • JetBrains Intellij Idea: before 2019.1 (fixed in 2019.1)

Published 2019-07-03. Last modified 2026-06-17.