Sploitus
Critical Vulnerabilities in GitHub Plugins and Git Affecting User Security
Article Content
Two critical vulnerabilities have been identified affecting GitHub integration in JetBrains IDE and Git version 2.45.0. CVE-2024-37051 allows unauthorized disclosure of GitHub access tokens through malicious pull requests in JetBrains IDE, risking access to private repositories. Users must update their IDE and revoke existing tokens immediately. CVE-2024-32002 enables remote command execution via git clone using vulnerable submodule configurations, requiring specific settings to exploit. Both vulnerabilities pose significant risks to users and organizations relying on these tools for development. Immediate action is recommended to mitigate potential breaches.
Key Points: • CVE-2024-37051 exposes GitHub tokens via malicious pull requests in JetBrains IDE. • CVE-2024-32002 allows remote command execution through vulnerable Git submodules. • Users must update software and revoke tokens to prevent unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.