Skip to main content

Acceptance of Extraneous Untrusted Data With Trusted Data

CVE-2023-51655

Severity Medium
Score 6.3/10

Summary

In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

  • HIGH
  • LOCAL
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • NONE

CWE-349 - Acceptance of Extraneous Untrusted Data With Trusted Data

The software, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

References

Advisory Timeline

  • Published