Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-37051

9.3 · CRITICAL
Published Jun 10, 2024 jetbrains CWE-522 EPSS 3.84% (89th pctl)

Overview

CVE-2024-37051 is a critical-severity vulnerability affecting jetbrains aqua. It was published on June 10, 2024 and has a CVSS 3.1 base score of 9.3 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.3, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

Remediation

Check the references section for vendor advisories and patches from jetbrains. Update aqua to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
jetbrains aqua >= 0, < 2024.1.2 Affected
jetbrains clion >= 0, < 2023.1.7 Affected
jetbrains datagrip >= 2023.1.0, < 2023.1.3 Affected
jetbrains dataspell >= 0, < 2023.1.6 Affected
jetbrains goland >= 0, < 2023.1.6 Affected
jetbrains intellij_idea >= 0, < 2023.1.7 Affected
jetbrains mps >= 0, < 2023.2.1 Affected
jetbrains phpstorm >= 0, < 2023.1.6 Affected
jetbrains pycharm >= 0, < 2023.1.6 Affected
jetbrains rider >= 0, < 2023.1.7 Affected
jetbrains rubymine >= 0, < 2023.1.7 Affected
jetbrains rustrover >= 0, < 2024.1.1 Affected
jetbrains webstorm >= 0, < 2023.1.6 Affected

Frequently Asked Questions

What is CVE-2024-37051?

CVE-2024-37051 is a critical-severity vulnerability affecting jetbrains aqua. It was published on June 10, 2024 and has a CVSS 3.1 base score of 9.3 (CRITICAL).

How severe is CVE-2024-37051?

This vulnerability has a CVSS 3.1 base score of 9.3, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2024-37051?

Check the references section for vendor advisories and patches from jetbrains. Update aqua to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-37051?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-37051 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.