First published: Tue May 11 2021(Updated: )
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains IntelliJ IDEA | <2020.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30006 is a vulnerability in IntelliJ IDEA before version 2020.3.3 that allows for XXE (XML External Entity) attacks, which can lead to information disclosure.
CVE-2021-30006 affects IntelliJ IDEA versions before 2020.3.3 and allows for XXE attacks, potentially resulting in information disclosure.
XXE stands for XML External Entity and it is a type of attack where an attacker can exploit a vulnerability to disclose internal files, execute remote code, or perform server-side request forgery.
To fix CVE-2021-30006, you should update IntelliJ IDEA to version 2020.3.3 or later, as this version includes a fix for the XXE vulnerability.
You can find more information about CVE-2021-30006 in the JetBrains Security Bulletin for Q1 2021, available at the following link: https://blog.jetbrains.com/blog/2021/05/07/jetbrains-security-bulletin-q1-2021/