CRITICAL · 9.3

CVE-2024-37051

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion ...

Vulnerability Description

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

CVSS Score

9.3

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
JetbrainsAqua< 2024.1.2
JetbrainsClion< 2023.1.7
JetbrainsDatagrip>= 2023.1.0, < 2023.1.3
JetbrainsDataspell< 2023.1.6
JetbrainsGoland< 2023.1.6
JetbrainsIntellij Idea< 2023.1.7
JetbrainsMps< 2023.2.1
JetbrainsPhpstorm< 2023.1.6
JetbrainsPycharm< 2023.1.6
JetbrainsRider< 2023.1.7
JetbrainsRubymine< 2023.1.7
JetbrainsRustrover< 2024.1.1
JetbrainsWebstorm< 2023.1.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-37051?

CVE-2024-37051 is a vulnerability with a CVSS score of 9.3 (CRITICAL). GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion ...

How severe is CVE-2024-37051?

CVE-2024-37051 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2024-37051?

Check the references section above for vendor advisories and patch information. Affected products include: Jetbrains Aqua, Jetbrains Clion, Jetbrains Datagrip, Jetbrains Dataspell, Jetbrains Goland.