GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
Conclusion & alert: CVE-2024-37051 is rated High Risk (68.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 6.32%, 91th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-20 | 6.48% | 6.32% | -0.16% |
| 2 | 2026-01-18 | 6.32% | 6.48% | +0.16% |
| 3 | 2025-11-21 | — | 6.32% | — |
Full EPSS history (25 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 3.1 | CRITICAL |
|
2.8 | 5.8 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| jetbrains | aqua | < 2024.1.2 | cpe:2.3:a:jetbrains:aqua:*:*:*:*:*:*:*:* |
| jetbrains | clion | < 2023.1.7 | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* |
| jetbrains | clion | >= 2023.2.0, < 2023.2.4 | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* |
| jetbrains | clion | >= 2023.3.0, < 2023.3.5 | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* |
| jetbrains | clion | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:clion:*:*:*:*:*:*:*:* |
| jetbrains | datagrip | >= 2023.1.0, < 2023.1.3 | cpe:2.3:a:jetbrains:datagrip:*:*:*:*:*:*:*:* |
| jetbrains | datagrip | >= 2023.2.0, < 2023.2.4 | cpe:2.3:a:jetbrains:datagrip:*:*:*:*:*:*:*:* |
| jetbrains | datagrip | >= 2023.3.0, < 2023.3.5 | cpe:2.3:a:jetbrains:datagrip:*:*:*:*:*:*:*:* |
| jetbrains | datagrip | >= 2024.1.0, < 2024.1.4 | cpe:2.3:a:jetbrains:datagrip:*:*:*:*:*:*:*:* |
| jetbrains | dataspell | < 2023.1.6 | cpe:2.3:a:jetbrains:dataspell:*:*:*:*:*:*:*:* |
| jetbrains | dataspell | >= 2023.2.0, < 2023.2.7 | cpe:2.3:a:jetbrains:dataspell:*:*:*:*:*:*:*:* |
| jetbrains | dataspell | >= 2023.3.0, < 2023.3.6 | cpe:2.3:a:jetbrains:dataspell:*:*:*:*:*:*:*:* |
| jetbrains | dataspell | >= 2024.1.0, < 2024.1.2 | cpe:2.3:a:jetbrains:dataspell:*:*:*:*:*:*:*:* |
| jetbrains | goland | < 2023.1.6 | cpe:2.3:a:jetbrains:goland:*:*:*:*:*:*:*:* |
| jetbrains | goland | >= 2023.2.0, < 2023.2.7 | cpe:2.3:a:jetbrains:goland:*:*:*:*:*:*:*:* |
| jetbrains | goland | >= 2023.3.0, < 2023.3.7 | cpe:2.3:a:jetbrains:goland:*:*:*:*:*:*:*:* |
| jetbrains | goland | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:goland:*:*:*:*:*:*:*:* |
| jetbrains | intellij_idea | < 2023.1.7 | cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:* |
| jetbrains | intellij_idea | >= 2023.2.0, < 2023.2.7 | cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:* |
| jetbrains | intellij_idea | >= 2023.3.0, < 2023.3.7 | cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:* |
| jetbrains | intellij_idea | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:intellij_idea:*:*:*:*:*:*:*:* |
| jetbrains | mps | < 2023.2.1 | cpe:2.3:a:jetbrains:mps:*:*:*:*:*:*:*:* |
| jetbrains | mps | 2023.3.0 | cpe:2.3:a:jetbrains:mps:2023.3.0:*:*:*:*:*:*:* |
| jetbrains | phpstorm | < 2023.1.6 | cpe:2.3:a:jetbrains:phpstorm:*:*:*:*:*:*:*:* |
| jetbrains | phpstorm | >= 2023.2.0, < 2023.2.6 | cpe:2.3:a:jetbrains:phpstorm:*:*:*:*:*:*:*:* |
| jetbrains | phpstorm | >= 2023.3.0, < 2023.3.7 | cpe:2.3:a:jetbrains:phpstorm:*:*:*:*:*:*:*:* |
| jetbrains | phpstorm | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:phpstorm:*:*:*:*:*:*:*:* |
| jetbrains | pycharm | < 2023.1.6 | cpe:2.3:a:jetbrains:pycharm:*:*:*:*:*:*:*:* |
| jetbrains | pycharm | >= 2023.2.0, < 2023.2.7 | cpe:2.3:a:jetbrains:pycharm:*:*:*:*:*:*:*:* |
| jetbrains | pycharm | >= 2023.3.0, < 2023.3.6 | cpe:2.3:a:jetbrains:pycharm:*:*:*:*:*:*:*:* |
| jetbrains | pycharm | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:pycharm:*:*:*:*:*:*:*:* |
| jetbrains | rider | < 2023.1.7 | cpe:2.3:a:jetbrains:rider:*:*:*:*:*:*:*:* |
| jetbrains | rider | >= 2023.2.0, < 2023.2.5 | cpe:2.3:a:jetbrains:rider:*:*:*:*:*:*:*:* |
| jetbrains | rider | >= 2023.3.0, < 2023.3.6 | cpe:2.3:a:jetbrains:rider:*:*:*:*:*:*:*:* |
| jetbrains | rider | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:rider:*:*:*:*:*:*:*:* |
| jetbrains | rubymine | < 2023.1.7 | cpe:2.3:a:jetbrains:rubymine:*:*:*:*:*:*:*:* |
| jetbrains | rubymine | >= 2023.2.0, < 2023.2.7 | cpe:2.3:a:jetbrains:rubymine:*:*:*:*:*:*:*:* |
| jetbrains | rubymine | >= 2023.3.0, < 2023.3.7 | cpe:2.3:a:jetbrains:rubymine:*:*:*:*:*:*:*:* |
| jetbrains | rubymine | >= 2024.1.0, < 2024.1.3 | cpe:2.3:a:jetbrains:rubymine:*:*:*:*:*:*:*:* |
| jetbrains | rustrover | < 2024.1.1 | cpe:2.3:a:jetbrains:rustrover:*:*:*:*:*:*:*:* |
| jetbrains | webstorm | < 2023.1.6 | cpe:2.3:a:jetbrains:webstorm:*:*:*:*:*:*:*:* |
| jetbrains | webstorm | >= 2023.2.0, < 2023.2.7 | cpe:2.3:a:jetbrains:webstorm:*:*:*:*:*:*:*:* |
| jetbrains | webstorm | >= 2023.3.0, < 2023.3.7 | cpe:2.3:a:jetbrains:webstorm:*:*:*:*:*:*:*:* |
| jetbrains | webstorm | >= 2024.1.0, < 2024.1.4 | cpe:2.3:a:jetbrains:webstorm:*:*:*:*:*:*:*:* |