Lucene search

K
cveJetBrainsCVE-2022-48435
HistoryApr 04, 2023 - 2:15 p.m.

CVE-2022-48435

2023-04-0414:15:08
CWE-532
JetBrains
web.nvd.nist.gov
26
cve-2022-48435
jetbrains
phpstorm
source code logging
vulnerability

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

9.0%

In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file

Affected configurations

Nvd
Node
jetbrainsphpstormRange<2023.1
VendorProductVersionCPE
jetbrainsphpstorm*cpe:2.3:a:jetbrains:phpstorm:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "JetBrains",
    "product": "PhpStorm",
    "versions": [
      {
        "version": "0",
        "status": "affected",
        "lessThan": "2023.1",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2022-48435