CVE-2024-37051
Published: Jun 10, 2024
Modified: Feb 13, 2025
CVSS v3.1
9.3
Description
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
| Vendor | Product | Versions |
|---|---|---|
JetBrains | IntelliJ IDEA | affected 2023.1 - < 2023.1.7affected 2023.1 - < 2023.2.7affected 2023.1 - < 2023.3.7affected 2023.1 - < 2024.1.3affected 2023.1 - < 2024.2 EAP3 |
JetBrains | Aqua | affected 0 - < 2024.1.2 |
JetBrains | CLion | affected 2023.1 - < 2023.1.7affected 2023.1 - < 2023.2.4affected 2023.1 - < 2023.3.5affected 2023.1 - < 2024.1.3affected 2023.1 - < 2024.2 EAP2 |
JetBrains | DataGrip | affected 2023.1 - < 2023.1.3affected 2023.1 - < 2023.2.4affected 2023.1 - < 2023.3.5affected 2023.1 - < 2024.1.4 |
JetBrains | DataSpell | affected 2023.1 - < 2023.1.6affected 2023.1 - < 2023.2.7affected 2023.1 - < 2023.3.6affected 2023.1 - < 2024.1.2affected 2023.1 - < 2024.2 EAP1 |
JetBrains | GoLand | affected 2023.1 - < 2023.1.6affected 2023.1 - < 2023.2.7affected 2023.1 - < 2023.3.7affected 2023.1 - < 2024.1.3affected 2023.1 - < 2024.2 EAP3 |
JetBrains | MPS | affected 2023.1 - < 2023.2.1affected 2023.1 - < 2023.3.1affected 2023.1 - < 2024.1 EAP2 |
JetBrains | PhpStorm | affected 2023.1 - < 2023.1.6affected 2023.1 - < 2023.2.6affected 2023.1 - < 2023.3.7affected 2023.1 - < 2024.1.3affected 2023.1 - < 2024.2 EAP3 |
JetBrains | PyCharm | affected 2023.1 - < 2023.1.6affected 2023.1 - < 2023.2.7affected 2023.1 - < 2023.3.6affected 2023.1 - < 2024.1.3affected 2023.1 - < 2024.2 EAP2 |
JetBrains | Rider | affected 2023.1 - < 2023.1.7affected 2023.1 - < 2023.2.5affected 2023.1 - < 2023.3.6affected 2023.1 - < 2024.1.3 |
JetBrains | RubyMine | affected 2023.1 - < 2023.1.7affected 2023.1 - < 2023.2.7affected 2023.1 - < 2023.3.7affected 2023.1 - < 2024.1.3affected 2023.1 - < 2024.2 EAP4 |
JetBrains | RustRover | affected 0 - < 2024.1.1 |
JetBrains | WebStorm | affected 2023.1 - < 2023.1.6affected 2023.1 - < 2023.2.7affected 2023.1 - < 2023.3.7affected 2023.1 - < 2024.1.4 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now