logo

JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens

ID: fd8cf914-2eb7-5135-9265-e50b0a99bba6

STIX ID: report--fd8cf914-2eb7-5135-9265-e50b0a99bba6

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

JetBrains warned of CVE-2024-37051, a critical vulnerability in IntelliJ-based IDEs (versions 2023.1 and later) when the JetBrains GitHub plugin is used; crafted pull request content could leak GitHub access tokens to an external host. JetBrains released patches, removed vulnerable plugin versions from the marketplace, and strongly advised updating affected IDEs and revoking any tokens used with the plugin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.