CVE-2021-45977

CRITICAL

JetBrains IDEs <2021.3.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://jetbrains.com

Scores

CVSS v3 9.8
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (7)
jetbrains/clion 2021.3.1
jetbrains/goland 2021.3.1
jetbrains/intellij_idea 2021.3.1 preview (2 CPE variants)
jetbrains/phpstorm 2021.3.1 preview (2 CPE variants)
jetbrains/pycharm 2021.3.1 2021.3.1
jetbrains/rubymine 2021.3.1 preview (2 CPE variants)
jetbrains/webstorm 2021.3.1 preview (2 CPE variants)
Published Feb 25, 2022
Tracked Since Feb 18, 2026