Medium
CVSS: 5.4
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
Medium
CVSS: 5.2
In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
Medium
CVSS: 6.5
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
Medium
CVSS: 6.5
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
Medium
CVSS: 4.7
In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference
Low
CVSS: 3.3
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file