CVE-2021-25756: Medium severity intellij idea vulnerability
Published Feb 3, 2021
·Updated
In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS.
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2020.2
Event History
Feb 3, 2021
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
Description
Frequently Asked Questions
1
What is CVE-2021-25756?
CVE-2021-25756 is a vulnerability in JetBrains IntelliJ IDEA before version 2020.2 where HTTP links were used for remote repositories instead of HTTPS.
2
What is the severity of CVE-2021-25756?
The severity of CVE-2021-25756 is medium with a CVSS score of 5.3.
3
How does CVE-2021-25756 affect JetBrains IntelliJ IDEA?
CVE-2021-25756 affects JetBrains IntelliJ IDEA before version 2020.2 by using HTTP links instead of HTTPS for several remote repositories.
4
How can I fix CVE-2021-25756?
To fix CVE-2021-25756, update JetBrains IntelliJ IDEA to version 2020.2 or newer, which uses HTTPS instead of HTTP for remote repositories.
5
Where can I find more information about CVE-2021-25756?
You can find more information about CVE-2021-25756 in the JetBrains Security Bulletin Q4 2020 on the JetBrains blog.