CVEFinder.io

CVE-2021-45977

⛔ critical
🔍 Scan for this CVE
Summary

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 20

Description

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

CVSS Score
9.8
Critical
EPSS Score
0.0
Exploit Probability
Published Date
2022-02-25
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 340,405 vulnerabilities in our database.

#32,269
Top 10% most severe
Severity Percentile
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

📦 Affected Products 7

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-64810 🔶 medium 4.3 0.2 In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi... 2026-07-23
CVE-2026-64811 ⚠️ high 7.8 0.1 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop... 2026-07-23
CVE-2026-64812 ⛔ critical 10.0 0.4 In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session 2026-07-23
CVE-2026-64813 ⛔ critical 10.0 0.4 In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session 2026-07-23
CVE-2026-64814 ⚠️ high 8.6 0.3 In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session 2026-07-23
CVE-2026-64815 ⚠️ high 8.1 0.3 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files 2026-07-23
These CVEs affect the same products