GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
In versions of JetBrains IDE released after 2023.1, the GitHub access token can be transferred or disclosed to third parties unintentionally by the user (however, user interaction is required — UI:R). The vulnerability is classified as CWE-522, which is insufficiently protected credentials, meaning the token is not adequately secured against leakage to untrusted external entities. The scope of the vulnerability exceeds the context of the attacked application (S:C — Changed Scope), which means that the effects may impact resources external to the IDE itself.
An attacker can obtain the victim's GitHub access token, potentially enabling them full access to repositories, source code, and other resources associated with the user's GitHub account. This results in high confidentiality (C:H) and high integrity (I:H) of compromised data.
Update the used JetBrains IDE to the versions indicated above as patched (or newer). Additionally, it is recommended to revoke and generate new GitHub tokens in all environments where vulnerable IDE versions were used. Detailed information is available on the vendor's website: https://www.jetbrains.com/privacy-security/issues-fixed/
JetBrains IDE in versions after 2023.1 and before the following patched releases: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NJetbrains Aqua
APPJetbrains< 2024.1.2Jetbrains Clion
APPJetbrains< 2023.1.72023.2.0 – 2023.2.4 (excl.)2023.3.0 – 2023.3.5 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Datagrip
APPJetbrains2023.1.0 – 2023.1.3 (excl.)2023.2.0 – 2023.2.4 (excl.)2023.3.0 – 2023.3.5 (excl.)2024.1.0 – 2024.1.4 (excl.)Jetbrains Dataspell
APPJetbrains< 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.6 (excl.)2024.1.0 – 2024.1.2 (excl.)Jetbrains Goland
APPJetbrains< 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Intellij Idea
APPJetbrains< 2023.1.72023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Mps
APPJetbrains2023.3.0< 2023.2.1Jetbrains Phpstorm
APPJetbrains< 2023.1.62023.2.0 – 2023.2.6 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Pycharm
APPJetbrains< 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.6 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Rider
APPJetbrains< 2023.1.72023.2.0 – 2023.2.5 (excl.)2023.3.0 – 2023.3.6 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Rubymine
APPJetbrains< 2023.1.72023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.3 (excl.)Jetbrains Rustrover
APPJetbrains< 2024.1.1Jetbrains Webstorm
APPJetbrains< 2023.1.62023.2.0 – 2023.2.7 (excl.)2023.3.0 – 2023.3.7 (excl.)2024.1.0 – 2024.1.4 (excl.)
Related vulnerabilities
JetBrains IntelliJ IDEA — nieautoryzowany input injection w sesji Remote Development
JetBrains IntelliJ IDEA – nieautoryzowana modyfikacja ustawień w sesji Remote Development
RCE poprzez path traversal w obsłudze ID przestrzeni roboczej w IntelliJ IDEA
JetBrains IDE (Remote Development) — nasłuch na 0.0.0.0 umożliwia nieautoryzowany dostęp
JetBrains WebStorm — wykonanie kodu bez potwierdzenia dla niezaufanych projektów