CVE Vulnerabilities

CVE-2024-52555

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Nov 15, 2024 | Modified: Jan 31, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

Name Vendor Start Version End Version
Webstorm Jetbrains * 2024.3.0 (excluding)

References