CVE-2024-37051 describes a critical vulnerability in JetBrains IDEs (versions 2023.1 and later, across numerous products like IntelliJ IDEA, PyCharm, and WebStorm) where GitHub access tokens could be inadvertently exposed to third-party sites. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, allowing an attacker to potentially compromise GitHub accounts by intercepting these tokens. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of concern within the cybersecurity community. Users are strongly advised to update their JetBrains IDEs to the patched versions to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024.1.2CPE matchmatch criteria | cpe:2.3:a:jetbrains:aqua:*:*:*:*:*:*:*:* | ||
< 2023.1.7CPE matchmatch criteria | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* | ||
>= 2023.2.0, < 2023.2.4CPE matchmatch criteria | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* | ||
>= 2023.3.0, < 2023.3.5CPE matchmatch criteria | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* | ||
>= 2024.1.0, < 2024.1.3CPE matchmatch criteria | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.