JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Intellij_idea | Jetbrains | * | 2019.2 (excluding) |
Intellij-community-idea | Ubuntu | groovy | * |
Intellij-community-idea | Ubuntu | hirsute | * |
Intellij-community-idea | Ubuntu | impish | * |
Intellij-community-idea | Ubuntu | kinetic | * |
Intellij-community-idea | Ubuntu | lunar | * |
Intellij-community-idea | Ubuntu | mantic | * |
Intellij-community-idea | Ubuntu | oracular | * |
Intellij-community-idea | Ubuntu | trusty | * |
Intellij-idea | Ubuntu | trusty | * |