CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-37051

CVSS 9.3v3.1pub. 2024-06-10upd. 2024-11-21

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

🤖 AI Analysis
How it works

In versions of JetBrains IDE released after 2023.1, the GitHub access token can be transferred or disclosed to third parties unintentionally by the user (however, user interaction is required — UI:R). The vulnerability is classified as CWE-522, which is insufficiently protected credentials, meaning the token is not adequately secured against leakage to untrusted external entities. The scope of the vulnerability exceeds the context of the attacked application (S:C — Changed Scope), which means that the effects may impact resources external to the IDE itself.

Impact

An attacker can obtain the victim's GitHub access token, potentially enabling them full access to repositories, source code, and other resources associated with the user's GitHub account. This results in high confidentiality (C:H) and high integrity (I:H) of compromised data.

Mitigation & patch

Update the used JetBrains IDE to the versions indicated above as patched (or newer). Additionally, it is recommended to revoke and generate new GitHub tokens in all environments where vulnerable IDE versions were used. Detailed information is available on the vendor's website: https://www.jetbrains.com/privacy-security/issues-fixed/

Who is affected

JetBrains IDE in versions after 2023.1 and before the following patched releases: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Jetbrains Aqua

    APP
    Jetbrains
    < 2024.1.2
  • Jetbrains Clion

    APP
    Jetbrains
    < 2023.1.72023.2.0 – 2023.2.4 (excl.)2023.3.0 – 2023.3.5 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Datagrip

    APP
    Jetbrains
    2023.1.0 – 2023.1.3 (excl.)2023.2.0 – 2023.2.4 (excl.)2023.3.0 – 2023.3.5 (excl.)2024.1.0 – 2024.1.4 (excl.)
  • Jetbrains Dataspell

    APP
    Jetbrains
    < 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.6 (excl.)2024.1.0 – 2024.1.2 (excl.)
  • Jetbrains Goland

    APP
    Jetbrains
    < 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Intellij Idea

    APP
    Jetbrains
    < 2023.1.72023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Mps

    APP
    Jetbrains
    2023.3.0< 2023.2.1
  • Jetbrains Phpstorm

    APP
    Jetbrains
    < 2023.1.62023.2.0 – 2023.2.6 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Pycharm

    APP
    Jetbrains
    < 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.6 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Rider

    APP
    Jetbrains
    < 2023.1.72023.2.0 – 2023.2.5 (excl.)2023.3.0 – 2023.3.6 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Rubymine

    APP
    Jetbrains
    < 2023.1.72023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)
  • Jetbrains Rustrover

    APP
    Jetbrains
    < 2024.1.1
  • Jetbrains Webstorm

    APP
    Jetbrains
    < 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-64812CRITICAL10.0PL ✓same product

JetBrains IntelliJ IDEA — nieautoryzowany input injection w sesji Remote Development

CVE-2026-64813CRITICAL10.0PL ✓same product

JetBrains IntelliJ IDEA – nieautoryzowana modyfikacja ustawień w sesji Remote Development

CVE-2026-59792CRITICAL9.6PL ✓same product

RCE poprzez path traversal w obsłudze ID przestrzeni roboczej w IntelliJ IDEA

CVE-2021-45977CRITICAL9.8PL ✓same product

JetBrains IDE (Remote Development) — nasłuch na 0.0.0.0 umożliwia nieautoryzowany dostęp

CVE-2021-31897CRITICAL9.8PL ✓same product

JetBrains WebStorm — wykonanie kodu bez potwierdzenia dla niezaufanych projektów