PT-2024-1694 · Jetbrains · Jetbrains Intellij Idea

Published

2024-02-06

·

Updated

2024-02-09

·

CVE-2024-24941

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions JetBrains IntelliJ IDEA versions prior to 2023.3.3
Description The issue exists due to insufficient input validation in the authentication token handler component of the integrated development environment. This could allow a remote attacker to send an authentication token to an arbitrary URL.
Recommendations For versions prior to 2023.3.3, update to version 2023.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin for JetBrains Space until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-01382
CVE-2024-24941

Affected Products

Jetbrains Intellij Idea