Today > | 1 Medium vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-37051

June 10, 2024, 6:06 p.m.

CVSS Score

9.3 / 10

Product(s) Impacted

JetBrains IntelliJ IDEA

  • 2023.1 - 2023.1.7
  • 2023.2 - 2023.2.7
  • 2023.3 - 2023.3.7
  • 2024.1 - 2024.1.3
  • 2024.2 EAP3

JetBrains Aqua

  • 2024.1.2

JetBrains CLion

  • 2023.1 - 2023.1.7
  • 2023.2 - 2023.2.4
  • 2023.3 - 2023.3.5
  • 2024.1 - 2024.1.3
  • 2024.2 EAP2

JetBrains DataGrip

  • 2023.1.3
  • 2023.2.4
  • 2023.3.5
  • 2024.1.4

JetBrains DataSpell

  • 2023.1.6
  • 2023.2.7
  • 2023.3.6
  • 2024.1.2
  • 2024.2 EAP1

JetBrains GoLand

  • 2023.1.6
  • 2023.2.7
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP3

JetBrains MPS

  • 2023.2.1
  • 2023.3.1
  • 2024.1 EAP2

JetBrains PhpStorm

  • 2023.1.6
  • 2023.2.6
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP3

JetBrains PyCharm

  • 2023.1.6
  • 2023.2.7
  • 2023.3.6
  • 2024.1.3
  • 2024.2 EAP2

JetBrains Rider

  • 2023.1.7
  • 2023.2.5
  • 2023.3.6
  • 2024.1.3

JetBrains RubyMine

  • 2023.1.7
  • 2023.2.7
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP4

JetBrains RustRover

  • 2024.1.1

JetBrains WebStorm

  • 2023.1.6
  • 2023.2.7
  • 2023.3.7
  • 2024.1.4

IntelliJ IDEA

  • 2023.1.7
  • 2023.2.7
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP3

Aqua

  • 2024.1.2

CLion

  • 2023.1.7
  • 2023.2.4
  • 2023.3.5
  • 2024.1.3
  • 2024.2 EAP2

DataGrip

  • 2023.1.3
  • 2023.2.4
  • 2023.3.5
  • 2024.1.4

DataSpell

  • 2023.1.6
  • 2023.2.7
  • 2023.3.6
  • 2024.1.2
  • 2024.2 EAP1

GoLand

  • 2023.1.6
  • 2023.2.7
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP3

MPS

  • 2023.2.1
  • 2023.3.1
  • 2024.1 EAP2

PhpStorm

  • 2023.1.6
  • 2023.2.6
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP3

PyCharm

  • 2023.1.6
  • 2023.2.7
  • 2023.3.6
  • 2024.1.3
  • 2024.2 EAP2

Rider

  • 2023.1.7
  • 2023.2.5
  • 2023.3.6
  • 2024.1.3

RubyMine

  • 2023.1.7
  • 2023.2.7
  • 2023.3.7
  • 2024.1.3
  • 2024.2 EAP4

RustRover

  • 2024.1.1

WebStorm

  • 2023.1.6
  • 2023.2.7
  • 2023.3.7
  • 2024.1.4

Description

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

Weaknesses

Date

Published: June 10, 2024, 4:15 p.m.

Last Modified: June 10, 2024, 6:06 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@jetbrains.com

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

Base Score
9.3
Exploitability Score
Impact Score
Base Severity
CRITICAL
CVSS Vector String

The CVSS vector string provides an in-depth view of the vulnerability metrics.

View Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

References