PT-2022-12478 · Jetbrains · Clion+6

Damian Gwiżdż

·

Published

2022-02-25

·

Updated

2022-03-08

·

CVE-2021-45977

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IntelliJ IDEA versions 2021.3.1 Preview through 2021.3.1 RC PyCharm Professional version 2021.3.1 RC GoLand version 2021.3.1 PhpStorm versions 2021.3.1 Preview through 2021.3.1 RC RubyMine versions 2021.3.1 Preview through 2021.3.1 RC CLion version 2021.3.1 WebStorm versions 2021.3.1 Preview through 2021.3.1 RC
Description The issue arises because the affected software versions bind to the 0.0.0.0 IP address when used as Remote Development backend IDEs.
Recommendations For IntelliJ IDEA version 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1. For PyCharm Professional version 2021.3.1 RC, update to version 2021.3.1. For GoLand version 2021.3.1, update to version 2021.3.2. For PhpStorm versions 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1 (213.6461.83). For RubyMine versions 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1. For CLion version 2021.3.1, update to version 2021.3.2. For WebStorm versions 2021.3.1 Preview or 2021.3.1 RC, update to version 2021.3.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-45977

Affected Products

Clion
Goland
Intellij Idea
Phpstorm
Pycharm Professional
Rubymine
Webstorm