PT-2022-12478 · Jetbrains · Clion+6
Damian Gwiżdż
·
Published
2022-02-25
·
Updated
2022-03-08
·
CVE-2021-45977
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IntelliJ IDEA versions 2021.3.1 Preview through 2021.3.1 RC
PyCharm Professional version 2021.3.1 RC
GoLand version 2021.3.1
PhpStorm versions 2021.3.1 Preview through 2021.3.1 RC
RubyMine versions 2021.3.1 Preview through 2021.3.1 RC
CLion version 2021.3.1
WebStorm versions 2021.3.1 Preview through 2021.3.1 RC
Description
The issue arises because the affected software versions bind to the 0.0.0.0 IP address when used as Remote Development backend IDEs.
Recommendations
For IntelliJ IDEA version 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1.
For PyCharm Professional version 2021.3.1 RC, update to version 2021.3.1.
For GoLand version 2021.3.1, update to version 2021.3.2.
For PhpStorm versions 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1 (213.6461.83).
For RubyMine versions 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1.
For CLion version 2021.3.1, update to version 2021.3.2.
For WebStorm versions 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clion
Goland
Intellij Idea
Phpstorm
Pycharm Professional
Rubymine
Webstorm