CVE-2022-28651
05.04.2022, 18:15
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fieldsEnginsight
Vendor | Product | Version |
---|---|---|
jetbrains | intellij_idea | 𝑥 < 2021.3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control SphereThe application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.