CVE Vulnerabilities

CVE-2021-45977

Published: Feb 25, 2022 | Modified: Mar 08, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

Affected Software

Name Vendor Start Version End Version
Clion Jetbrains 2021.3.1 (including) 2021.3.1 (including)
Goland Jetbrains 2021.3.1 (including) 2021.3.1 (including)
Intellij_idea Jetbrains 2021.3.1-preview (including) 2021.3.1-preview (including)
Intellij_idea Jetbrains 2021.3.1-rc (including) 2021.3.1-rc (including)
Phpstorm Jetbrains 2021.3.1-preview (including) 2021.3.1-preview (including)
Phpstorm Jetbrains 2021.3.1-rc (including) 2021.3.1-rc (including)
Pycharm Jetbrains 2021.3.1-2021.3.1 (including) 2021.3.1-2021.3.1 (including)
Rubymine Jetbrains 2021.3.1-preview (including) 2021.3.1-preview (including)
Rubymine Jetbrains 2021.3.1-rc (including) 2021.3.1-rc (including)
Webstorm Jetbrains 2021.3.1-preview (including) 2021.3.1-preview (including)
Webstorm Jetbrains 2021.3.1-rc (including) 2021.3.1-rc (including)

References