Threat Advisory

JetBrains Warns of IntelliJ IDE Bug Exposing GitHub Access Tokens

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Software development sector
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

JetBrains recently issued a critical security warning regarding a vulnerability, tracked as CVE-2024-37051, affecting its IntelliJ integrated development environment (IDE) applications. This flaw, present in IntelliJ-based IDEs from version 2023.1 onwards, potentially exposes GitHub access tokens when the JetBrains GitHub plugin is enabled and configured. The vulnerability was reported externally on May 29, 2024, raising concerns about potential exploitation through malicious content within GitHub pull requests.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

JetBrains recently issued a critical security warning regarding a vulnerability, tracked as CVE-2024-37051, affecting its IntelliJ integrated development environment (IDE) applications. This flaw, present in IntelliJ-based IDEs from version 2023.1 onwards, potentially exposes GitHub access tokens when the JetBrains GitHub plugin is enabled and configured. The vulnerability was reported externally on May 29, 2024, raising concerns about potential exploitation through malicious content within GitHub pull requests.[emaillocker id="1283"]

The vulnerability could allow third parties to obtain GitHub access tokens when handling pull requests within affected IDEs, compromising users' GitHub accounts. JetBrains promptly responded by releasing security updates for impacted IDE versions, urging users to patch their software immediately. They have also removed vulnerable versions of the JetBrains GitHub plugin from their official marketplace.

RECOMMENDATION:

We strongly recommend you update the following IDEs to given versions:

  • Aqua: 2024.1.2
  • CLion: 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2
  • DataGrip: 2024.1.4
  • DataSpell: 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2
  • GoLand: 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3
  • IntelliJ IDEA: 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3
  • MPS: 2023.2.1, 2023.3.1, 2024.1 EAP2
  • PhpStorm: 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3
  • PyCharm: 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2
  • Rider: 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3
  • RubyMine: 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4
  • RustRover: 2024.1.1
  • WebStorm: 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/jetbrains-warns-of-intellij-ide-bug-exposing-github-access-tokens/

[/emaillocker]
crossmenu