CVE Vulnerabilities

CVE-2021-45977

Published: Feb 25, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

Affected Software

NameVendorStart VersionEnd Version
ClionJetbrains2021.3.1 (including)2021.3.1 (including)
GolandJetbrains2021.3.1 (including)2021.3.1 (including)
Intellij_ideaJetbrains2021.3.1-preview (including)2021.3.1-preview (including)
Intellij_ideaJetbrains2021.3.1-rc (including)2021.3.1-rc (including)
PhpstormJetbrains2021.3.1-preview (including)2021.3.1-preview (including)
PhpstormJetbrains2021.3.1-rc (including)2021.3.1-rc (including)
PycharmJetbrains2021.3.1-2021.3.1 (including)2021.3.1-2021.3.1 (including)
RubymineJetbrains2021.3.1-preview (including)2021.3.1-preview (including)
RubymineJetbrains2021.3.1-rc (including)2021.3.1-rc (including)
WebstormJetbrains2021.3.1-preview (including)2021.3.1-preview (including)
WebstormJetbrains2021.3.1-rc (including)2021.3.1-rc (including)

References