Candidate: CVE-2019-9186 PublicDate: 2019-07-03 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9186 Description: In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_intellij-community-idea: upstream_intellij-community-idea: needs-triage precise/esm_intellij-community-idea: DNE trusty_intellij-community-idea: ignored (out of standard support) trusty/esm_intellij-community-idea: DNE xenial_intellij-community-idea: DNE bionic_intellij-community-idea: DNE focal_intellij-community-idea: DNE groovy_intellij-community-idea: ignored (reached end-of-life) hirsute_intellij-community-idea: ignored (reached end-of-life) impish_intellij-community-idea: needs-triage jammy_intellij-community-idea: needs-triage devel_intellij-community-idea: needs-triage