
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-37051 is a critical vulnerability affecting JetBrains IDEs released after version 2023.1. The vulnerability was discovered on May 29, 2024, and affects multiple JetBrains products including IntelliJ IDEA, Aqua, CLion, DataGrip, DataSpell, GoLand, MPS, PhpStorm, PyCharm, Rider, RubyMine, RustRover, and WebStorm. The issue involves the potential exposure of GitHub access tokens to third-party sites through the JetBrains GitHub plugin on the IntelliJ open-source platform (Help Net Security).
The vulnerability is classified as CWE-522 (Insufficiently Protected Credentials) with a CVSS v3.1 base score of 9.3 (Critical) according to JetBrains, and 7.5 (High) according to NVD. The vulnerability specifically affects the pull request functionality within the IDE, where malicious content as part of a pull request to a GitHub project could expose access tokens to a third-party host (Help Net Security, NVD).
If successfully exploited, attackers could gain unauthorized access to user GitHub accounts and repositories through the compromised access tokens. This access could potentially allow attackers to deploy malicious code or delete repositories (Help Net Security).
According to JetBrains, there is no confirmed evidence that attackers actively exploited the vulnerability before its discovery and disclosure. The vulnerability affects users who have the GitHub plugin enabled and configured in their IDE (Help Net Security).
JetBrains has released fixes for all affected IDEs and recommends users update to the latest available version. Users who have used the GitHub pull request functionality should: 1) Revoke GitHub access tokens being used by the plugin, 2) Revoke access for the JetBrains IDE Integration application, and 3) Delete the token issued for the plugin. Users of Google's Android Studio should upgrade to v2023.3.1.20 (Help Net Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."