Cleartext Storage of Server Credentials in JetBrains IntelliJ IDEA

Cleartext Storage of Server Credentials in JetBrains IntelliJ IDEA

CVE-2019-9823 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.

Learn more about our Cis Benchmark Audit For Server Software.