Vulnerability Description
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jetbrains | Aqua | < 2024.1.2 |
| Jetbrains | Clion | < 2023.1.7 |
| Jetbrains | Datagrip | >= 2023.1.0, < 2023.1.3 |
| Jetbrains | Dataspell | < 2023.1.6 |
| Jetbrains | Goland | < 2023.1.6 |
| Jetbrains | Intellij Idea | < 2023.1.7 |
| Jetbrains | Mps | < 2023.2.1 |
| Jetbrains | Phpstorm | < 2023.1.6 |
| Jetbrains | Pycharm | < 2023.1.6 |
| Jetbrains | Rider | < 2023.1.7 |
| Jetbrains | Rubymine | < 2023.1.7 |
| Jetbrains | Rustrover | < 2024.1.1 |
| Jetbrains | Webstorm | < 2023.1.6 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20240705-0004/
- https://www.jetbrains.com/privacy-security/issues-fixed/Vendor Advisory
- https://security.netapp.com/advisory/ntap-20240705-0004/
- https://www.jetbrains.com/privacy-security/issues-fixed/Vendor Advisory
FAQ
What is CVE-2024-37051?
CVE-2024-37051 is a vulnerability with a CVSS score of 9.3 (CRITICAL). GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion ...
How severe is CVE-2024-37051?
CVE-2024-37051 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-37051?
Check the references section above for vendor advisories and patch information. Affected products include: Jetbrains Aqua, Jetbrains Clion, Jetbrains Datagrip, Jetbrains Dataspell, Jetbrains Goland.