CVE Database
/

CVE-2024-37051

Back to search

CVE-2024-37051

Published: Jun 10, 2024

Modified: Feb 13, 2025

PUBLISHED

CVSS v3.1

9.3

CRITICAL

Description

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

VendorProductVersions

JetBrains

IntelliJ IDEA

affected
2023.1 - < 2023.1.7
affected
2023.1 - < 2023.2.7
affected
2023.1 - < 2023.3.7
affected
2023.1 - < 2024.1.3
affected
2023.1 - < 2024.2 EAP3

JetBrains

Aqua

affected
0 - < 2024.1.2

JetBrains

CLion

affected
2023.1 - < 2023.1.7
affected
2023.1 - < 2023.2.4
affected
2023.1 - < 2023.3.5
affected
2023.1 - < 2024.1.3
affected
2023.1 - < 2024.2 EAP2

JetBrains

DataGrip

affected
2023.1 - < 2023.1.3
affected
2023.1 - < 2023.2.4
affected
2023.1 - < 2023.3.5
affected
2023.1 - < 2024.1.4

JetBrains

DataSpell

affected
2023.1 - < 2023.1.6
affected
2023.1 - < 2023.2.7
affected
2023.1 - < 2023.3.6
affected
2023.1 - < 2024.1.2
affected
2023.1 - < 2024.2 EAP1

JetBrains

GoLand

affected
2023.1 - < 2023.1.6
affected
2023.1 - < 2023.2.7
affected
2023.1 - < 2023.3.7
affected
2023.1 - < 2024.1.3
affected
2023.1 - < 2024.2 EAP3

JetBrains

MPS

affected
2023.1 - < 2023.2.1
affected
2023.1 - < 2023.3.1
affected
2023.1 - < 2024.1 EAP2

JetBrains

PhpStorm

affected
2023.1 - < 2023.1.6
affected
2023.1 - < 2023.2.6
affected
2023.1 - < 2023.3.7
affected
2023.1 - < 2024.1.3
affected
2023.1 - < 2024.2 EAP3

JetBrains

PyCharm

affected
2023.1 - < 2023.1.6
affected
2023.1 - < 2023.2.7
affected
2023.1 - < 2023.3.6
affected
2023.1 - < 2024.1.3
affected
2023.1 - < 2024.2 EAP2

JetBrains

Rider

affected
2023.1 - < 2023.1.7
affected
2023.1 - < 2023.2.5
affected
2023.1 - < 2023.3.6
affected
2023.1 - < 2024.1.3

JetBrains

RubyMine

affected
2023.1 - < 2023.1.7
affected
2023.1 - < 2023.2.7
affected
2023.1 - < 2023.3.7
affected
2023.1 - < 2024.1.3
affected
2023.1 - < 2024.2 EAP4

JetBrains

RustRover

affected
0 - < 2024.1.1

JetBrains

WebStorm

affected
2023.1 - < 2023.1.6
affected
2023.1 - < 2023.2.7
affected
2023.1 - < 2023.3.7
affected
2023.1 - < 2024.1.4

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now