Insecure HTTP Requests in JetBrains WebStorm Affecting Multiple Versions
CVE-2021-31898

7.5HIGH

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
11 May 2021

Summary

JetBrains WebStorm versions prior to 2021.1 are susceptible to vulnerabilities due to the use of insecure HTTP requests instead of secure HTTPS connections. This oversight can lead to potential interception of sensitive data transmitted over the network, exposing users to various security risks. It is crucial for organizations using affected versions to upgrade to the latest release to ensure secure data communication.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.