← Vulnerability feed

Vulnerability record · CVE-2021-45977 · published 25 February 2022

CVE-2021-45977: Jetbrains clion vulnerability

Jetbrains · Clion

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

9.8 CVSS 3.1 Critical EPSS 1.1% · top 36.2%
9.8CVSS 3.1 base score, v2 7.5
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-45977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-64812Jetbrains intellij idea missing authentication for critical function vulnerabilityIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.48%10.0CVE-2026-64813Jetbrains intellij idea vulnerabilityIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development sessionEPSS 0.52%9.8CVE-2026-64815Jetbrains intellij idea code injection vulnerabilityIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form filesEPSS 0.48%9.8CVE-2026-59792Jetbrains intellij idea relative path traversal vulnerabilityIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possibleEPSS 0.61%9.8CVE-2023-51655Jetbrains intellij idea insufficient verification of data authenticity vulnerabilityIn JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the p…EPSS 0.33%9.8CVE-2020-11690Jetbrains intellij idea vulnerabilityIn JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.EPSS 2.3%9.8CVE-2019-9186Jetbrains intellij idea exposure of resource to wrong sphere vulnerabilityIn several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when t…EPSS 4.5%9.8CVE-2019-9823Jetbrains intellij idea cleartext storage of sensitive data vulnerabilityIn several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of t…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-45977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.