7.8
CVE-2022-48431
- EPSS 0%
- Veröffentlicht 29.03.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 07:33:20
- Quelle cve@jetbrains.com
- CVE-Watchlists
- Unerledigt
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JetBrains ≫ IntelliJ IDEA Version < 2023.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0% | 0 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| cve@jetbrains.com | 4.5 | 1 | 3.4 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.