CVE-2024-37051
June 10, 2024, 6:06 p.m.
Tags
CVSS Score
Product(s) Impacted
JetBrains IntelliJ IDEA
- 2023.1 - 2023.1.7
- 2023.2 - 2023.2.7
- 2023.3 - 2023.3.7
- 2024.1 - 2024.1.3
- 2024.2 EAP3
JetBrains Aqua
- 2024.1.2
JetBrains CLion
- 2023.1 - 2023.1.7
- 2023.2 - 2023.2.4
- 2023.3 - 2023.3.5
- 2024.1 - 2024.1.3
- 2024.2 EAP2
JetBrains DataGrip
- 2023.1.3
- 2023.2.4
- 2023.3.5
- 2024.1.4
JetBrains DataSpell
- 2023.1.6
- 2023.2.7
- 2023.3.6
- 2024.1.2
- 2024.2 EAP1
JetBrains GoLand
- 2023.1.6
- 2023.2.7
- 2023.3.7
- 2024.1.3
- 2024.2 EAP3
JetBrains MPS
- 2023.2.1
- 2023.3.1
- 2024.1 EAP2
JetBrains PhpStorm
- 2023.1.6
- 2023.2.6
- 2023.3.7
- 2024.1.3
- 2024.2 EAP3
JetBrains PyCharm
- 2023.1.6
- 2023.2.7
- 2023.3.6
- 2024.1.3
- 2024.2 EAP2
JetBrains Rider
- 2023.1.7
- 2023.2.5
- 2023.3.6
- 2024.1.3
JetBrains RubyMine
- 2023.1.7
- 2023.2.7
- 2023.3.7
- 2024.1.3
- 2024.2 EAP4
JetBrains RustRover
- 2024.1.1
JetBrains WebStorm
- 2023.1.6
- 2023.2.7
- 2023.3.7
- 2024.1.4
IntelliJ IDEA
- 2023.1.7
- 2023.2.7
- 2023.3.7
- 2024.1.3
- 2024.2 EAP3
Aqua
- 2024.1.2
CLion
- 2023.1.7
- 2023.2.4
- 2023.3.5
- 2024.1.3
- 2024.2 EAP2
DataGrip
- 2023.1.3
- 2023.2.4
- 2023.3.5
- 2024.1.4
DataSpell
- 2023.1.6
- 2023.2.7
- 2023.3.6
- 2024.1.2
- 2024.2 EAP1
GoLand
- 2023.1.6
- 2023.2.7
- 2023.3.7
- 2024.1.3
- 2024.2 EAP3
MPS
- 2023.2.1
- 2023.3.1
- 2024.1 EAP2
PhpStorm
- 2023.1.6
- 2023.2.6
- 2023.3.7
- 2024.1.3
- 2024.2 EAP3
PyCharm
- 2023.1.6
- 2023.2.7
- 2023.3.6
- 2024.1.3
- 2024.2 EAP2
Rider
- 2023.1.7
- 2023.2.5
- 2023.3.6
- 2024.1.3
RubyMine
- 2023.1.7
- 2023.2.7
- 2023.3.7
- 2024.1.3
- 2024.2 EAP4
RustRover
- 2024.1.1
WebStorm
- 2023.1.6
- 2023.2.7
- 2023.3.7
- 2024.1.4
Description
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
Weaknesses
Date
Published: June 10, 2024, 4:15 p.m.
Last Modified: June 10, 2024, 6:06 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@jetbrains.com
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
Exploitability Score
Impact Score
Base Severity
CRITICALCVSS Vector String
The CVSS vector string provides an in-depth view of the vulnerability metrics.
View Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N