EXECUTIVE SUMMARY
JetBrains recently issued a critical security warning regarding a vulnerability, tracked as CVE-2024-37051, affecting its IntelliJ integrated development environment (IDE) applications. This flaw, present in IntelliJ-based IDEs from version 2023.1 onwards, potentially exposes GitHub access tokens when the JetBrains GitHub plugin is enabled and configured. The vulnerability was reported externally on May 29, 2024, raising concerns about potential exploitation through malicious content within GitHub pull requests.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
JetBrains recently issued a critical security warning regarding a vulnerability, tracked as CVE-2024-37051, affecting its IntelliJ integrated development environment (IDE) applications. This flaw, present in IntelliJ-based IDEs from version 2023.1 onwards, potentially exposes GitHub access tokens when the JetBrains GitHub plugin is enabled and configured. The vulnerability was reported externally on May 29, 2024, raising concerns about potential exploitation through malicious content within GitHub pull requests.[emaillocker id="1283"]
The vulnerability could allow third parties to obtain GitHub access tokens when handling pull requests within affected IDEs, compromising users' GitHub accounts. JetBrains promptly responded by releasing security updates for impacted IDE versions, urging users to patch their software immediately. They have also removed vulnerable versions of the JetBrains GitHub plugin from their official marketplace.
RECOMMENDATION:
We strongly recommend you update the following IDEs to given versions:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]