CVE-2021-25758

In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:*

History

10 Dec 2021, 18:13

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 4.6
v3 : 7.8

02 Mar 2021, 18:15

Type Values Removed Values Added
Summary In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to code execution. In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to local code execution.

05 Feb 2021, 03:04

Type Values Removed Values Added
CWE CWE-502
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
References (MISC) https://blog.jetbrains.com - (MISC) https://blog.jetbrains.com - Product
References (MISC) https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/ - (MISC) https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/ - Vendor Advisory
CPE cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:*

03 Feb 2021, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-03 16:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-25758

Mitre link : CVE-2021-25758

CVE.ORG link : CVE-2021-25758


JSON object : View

Products Affected

jetbrains

  • intellij_idea
CWE
CWE-502

Deserialization of Untrusted Data