CVE-2021-30005
HIGHCVSS 7.8/10EPSS 0.85%
Last modified
CVE-2021-30005 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jetbrains | Pycharm | < 2020.3.4 |
References
- https://blog.jetbrains.comVendor Advisory
- https://security.gentoo.org/glsa/202107-45Third Party Advisory
- https://blog.jetbrains.comVendor Advisory
- https://security.gentoo.org/glsa/202107-45Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30005?
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
How severe is CVE-2021-30005?
CVE-2021-30005 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.85% probability of exploitation in the next 30 days.
How do I fix CVE-2021-30005?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-29998An issue was discovered in Wind River VxWorks before 6.5. Th…9.8
- CVE-2021-29999An issue was discovered in Wind River VxWorks through 6.8. T…9.8
- CVE-2021-30000An issue was discovered in LATRIX 0.6.0. SQL injection in th…9.8
- CVE-2021-30002An issue was discovered in the Linux kernel before 5.11.3 wh…6.2
- CVE-2021-30003An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 dev…4.8
- CVE-2021-30004In wpa_supplicant and hostapd 2.9, forging attacks may occur…5.3
- CVE-2021-30006In IntelliJ IDEA before 2020.3.3, XXE was possible, leading …7.5
- CVE-2021-30014There is a integer overflow in media_tools/av_parsers.c in t…5.5
- CVE-2021-30015There is a Null Pointer Dereference in function filter_core/…5.5
- CVE-2021-30019In the adts_dmx_process function in filters/reframe_adts.c i…5.5
- CVE-2021-3002Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/lo…6.1
- CVE-2021-30020In the function gf_hevc_read_pps_bs_internal function in med…5.5
Are you affected by CVE-2021-30005?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
