JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens
ID: fd8cf914-2eb7-5135-9265-e50b0a99bba6
STIX ID: report--fd8cf914-2eb7-5135-9265-e50b0a99bba6
Feed Name: Bleeping Computer
Threat Score
JetBrains warned of CVE-2024-37051, a critical vulnerability in IntelliJ-based IDEs (versions 2023.1 and later) when the JetBrains GitHub plugin is used; crafted pull request content could leak GitHub access tokens to an external host. JetBrains released patches, removed vulnerable plugin versions from the marketplace, and strongly advised updating affected IDEs and revoking any tokens used with the plugin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
