CVE-2021-31897: Critical severity webstorm vulnerability
Published May 11, 2021
·Updated
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.
Affected Software
1 affected component
JetBrains WebStorm<2021.1
Event History
May 11, 2021
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-31897.
2
What is the severity of CVE-2021-31897?
CVE-2021-31897 has a severity level of critical, with a value of 9.8.
3
What software is affected by CVE-2021-31897?
JetBrains WebStorm versions up to and excluding 2021.1 are affected by CVE-2021-31897.
4
What was the issue with JetBrains WebStorm before 2021.1?
Before version 2021.1, JetBrains WebStorm allowed code execution without user confirmation for untrusted projects.
5
How can I fix CVE-2021-31897?
To fix CVE-2021-31897, users should update JetBrains WebStorm to version 2021.1 or newer.