Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2024-37051
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-37051 is a critical vulnerability affecting JetBrains IDEs released after version 2023.1. The vulnerability was discovered on May 29, 2024, and affects multiple JetBrains products including IntelliJ IDEA, Aqua, CLion, DataGrip, DataSpell, GoLand, MPS, PhpStorm, PyCharm, Rider, RubyMine, RustRover, and WebStorm. The issue involves the potential exposure of GitHub access tokens to third-party sites through the JetBrains GitHub plugin on the IntelliJ open-source platform (Help Net Security).

Technical details

The vulnerability is classified as CWE-522 (Insufficiently Protected Credentials) with a CVSS v3.1 base score of 9.3 (Critical) according to JetBrains, and 7.5 (High) according to NVD. The vulnerability specifically affects the pull request functionality within the IDE, where malicious content as part of a pull request to a GitHub project could expose access tokens to a third-party host (Help Net Security, NVD).

Impact

If successfully exploited, attackers could gain unauthorized access to user GitHub accounts and repositories through the compromised access tokens. This access could potentially allow attackers to deploy malicious code or delete repositories (Help Net Security).

Exploitability

According to JetBrains, there is no confirmed evidence that attackers actively exploited the vulnerability before its discovery and disclosure. The vulnerability affects users who have the GitHub plugin enabled and configured in their IDE (Help Net Security).

Mitigation and workarounds

JetBrains has released fixes for all affected IDEs and recommends users update to the latest available version. Users who have used the GitHub pull request functionality should: 1) Revoke GitHub access tokens being used by the plugin, 2) Revoke access for the JetBrains IDE Integration application, and 3) Delete the token issued for the plugin. Users of Google's Android Studio should upgrade to v2023.3.1.20 (Help Net Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoNoSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management