CVE-2022-37009

Summary

In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible

Affected Software

VendorProductVersion RangeStatus
JetBrainsIntelliJ IDEA2022.2 < 2022.2affected

Weaknesses

  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References