In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
{
"binaries": [
{
"binary_name": "libintellij-core-java",
"binary_version": "183.5153.4-2"
},
{
"binary_name": "libintellij-extensions-java",
"binary_version": "183.5153.4-2"
},
{
"binary_name": "libintellij-jps-model-java",
"binary_version": "183.5153.4-2"
},
{
"binary_name": "libintellij-platform-api-java",
"binary_version": "183.5153.4-2"
},
{
"binary_name": "libintellij-platform-impl-java",
"binary_version": "183.5153.4-2"
},
{
"binary_name": "libintellij-utils-java",
"binary_version": "183.5153.4-2"
}
]
}
{
"binaries": [
{
"binary_name": "libintellij-core-java",
"binary_version": "183.5153.4-4ubuntu1"
},
{
"binary_name": "libintellij-extensions-java",
"binary_version": "183.5153.4-4ubuntu1"
},
{
"binary_name": "libintellij-jps-model-java",
"binary_version": "183.5153.4-4ubuntu1"
},
{
"binary_name": "libintellij-platform-api-java",
"binary_version": "183.5153.4-4ubuntu1"
},
{
"binary_name": "libintellij-platform-impl-java",
"binary_version": "183.5153.4-4ubuntu1"
},
{
"binary_name": "libintellij-utils-java",
"binary_version": "183.5153.4-4ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "libintellij-core-java",
"binary_version": "183.5153.4-6"
},
{
"binary_name": "libintellij-extensions-java",
"binary_version": "183.5153.4-6"
},
{
"binary_name": "libintellij-jps-model-java",
"binary_version": "183.5153.4-6"
},
{
"binary_name": "libintellij-platform-api-java",
"binary_version": "183.5153.4-6"
},
{
"binary_name": "libintellij-platform-impl-java",
"binary_version": "183.5153.4-6"
},
{
"binary_name": "libintellij-utils-java",
"binary_version": "183.5153.4-6"
}
]
}
{
"binaries": [
{
"binary_name": "libintellij-core-java",
"binary_version": "183.5153.4-7"
},
{
"binary_name": "libintellij-extensions-java",
"binary_version": "183.5153.4-7"
},
{
"binary_name": "libintellij-jps-model-java",
"binary_version": "183.5153.4-7"
},
{
"binary_name": "libintellij-platform-api-java",
"binary_version": "183.5153.4-7"
},
{
"binary_name": "libintellij-platform-impl-java",
"binary_version": "183.5153.4-7"
},
{
"binary_name": "libintellij-utils-java",
"binary_version": "183.5153.4-7"
}
]
}