First published: Tue May 11 2021(Updated: )
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains WebStorm | <2021.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-31897.
CVE-2021-31897 has a severity level of critical, with a value of 9.8.
JetBrains WebStorm versions up to and excluding 2021.1 are affected by CVE-2021-31897.
Before version 2021.1, JetBrains WebStorm allowed code execution without user confirmation for untrusted projects.
To fix CVE-2021-31897, users should update JetBrains WebStorm to version 2021.1 or newer.