JetBrains Pycharm
By the Year
In 2024 there have been 1 vulnerability in JetBrains Pycharm with an average score of 7.5 out of ten. Pycharm did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2024 as compared to last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 1 | 7.50 |
2023 | 0 | 0.00 |
2022 | 3 | 7.00 |
2021 | 1 | 7.80 |
2020 | 0 | 0.00 |
2019 | 1 | 7.50 |
2018 | 0 | 0.00 |
It may take a day or so for new Pycharm vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JetBrains Pycharm Security Vulnerabilities
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7
CVE-2024-37051
7.5 - High
- June 10, 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
Insufficiently Protected Credentials
In JetBrains Rider before 2022.1 local code execution
CVE-2022-29821
7.7 - High
- April 28, 2022
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
Code Injection
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
CVE-2022-29820
3.5 - Low
- April 28, 2022
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
Exposure of Resource to Wrong Sphere
JetBrains IntelliJ IDEA 2021.3.1 Preview
CVE-2021-45977
9.8 - Critical
- February 25, 2022
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm 2021.3.1 RC (used as Remote Development backend IDEs) bind to the 0.0.0.0 IP address. The fixed versions are: IntelliJ IDEA 2021.3.1, PyCharm Professional 2021.3.1, GoLand 2021.3.2, PhpStorm 2021.3.1 (213.6461.83), RubyMine 2021.3.1, CLion 2021.3.2, and WebStorm 2021.3.1.
In JetBrains PyCharm before 2020.3.4, local code execution was possible
CVE-2021-30005
7.8 - High
- May 11, 2021
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
Insufficient Verification of Data Authenticity
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes
CVE-2019-14958
7.5 - High
- October 02, 2019
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.
Allocation of Resources Without Limits or Throttling
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for JetBrains Pycharm or by JetBrains? Click the Watch button to subscribe.
![subscribe](/images/undraw_subscriber_vabu.png)