¡¾Â©¶´Í¨¸æ¡¿JetBrains IntelliJ IDEÐÅϢй¶©¶´£¨CVE-2024-37051£©

Ðû²¼Ê±¼ä 2024-06-13


Ò»¡¢Â©¶´¸ÅÊö

©¶´Ãû³Æ

   JetBrains IntelliJ IDEÐÅϢй¶©¶´

CVE   ID

CVE-2024-37051

©¶´ÀàÐÍ

ÐÅϢй¶

·¢ÏÖʱ¼ä

2024-06-12

©¶´ÆÀ·Ö

9.3

©¶´Æ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

ÊÇ

PoC/EXP

ÒѹûÈ»

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ

 

JetBrains IntelliJ ÊÇÒ»¸ö¼¯³É¿ª·¢»·¾³£¨IDE£©Æ½Ì¨ £¬ÓÉ JetBrains ¹«Ë¾¿ª·¢²¢Î¬»¤ £¬Ö§³ÖJava¡¢Kotlin¡¢Scala¡¢Groovy¡¢Python¡¢JavaScript¡¢TypeScript¡¢Go¡¢Rust µÈ¶àÖÖ±à³ÌÓïÑÔ¡£

2024Äê6ÔÂ12ÈÕ £¬¶¶È¦Îª¶Ä¶øÉú¼¯ÍÅVSRC¼à²âµ½ JetBrains IntelliJ IDEÐÅϢй¶©¶´£¨CVE-2024-37051£©µÄ©¶´Ï¸½Ú¼°PoC/EXPÔÚ»¥ÁªÍøÉϹûÈ» £¬¸Ã©¶´µÄCVSSÆÀ·ÖΪ9.3¡£

JetBrains IntelliJƽ̨É쵀 JetBrains GitHub ²å¼þÖдæÔÚ©¶´ £¬µ±ÔÚ IDEÖÐʹÓà GitHub À­È¡ÇëÇó¹¦Ð§Ê±¿ÉÄܵ¼Ö½«·ÃÎÊÁîÅÆÌ»Â¶¸øµÚÈý·½Ö÷»ú £¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¸Ã©¶´Ó°Ïì´Ó2023.1 ÆðÆôÓò¢ÅäÖÃ/ʹÓà JetBrains GitHub ²å¼þµÄËùÓлùÓÚIntelliJ µÄ¼¯³É¿ª·¢»·¾³¡£

 

 

¶þ¡¢Ó°Ï췶Χ

IntelliJ IDE 2023.1¼°¸ü¸ß°æ±¾ £¬ÆäÖÐÆôÓò¢ÅäÖÃÁËJetBrains GitHub ²å¼þ

 

 

Èý¡¢Äþ¾²´ëÊ©

3.1 Éý¼¶°æ±¾

ĿǰJetBrainsÒÑÐÞ¸´¸Ã©¶´ £¬²¢ÐÞ²¹ÁËÒ×Êܹ¥»÷µÄ JetBrains GitHub ²å¼þ £¬²¢´ÓÆä¹Ù·½²å¼þÊг¡ÖÐɾ³ýÁËËùÓÐÒÔǰÊÜÓ°ÏìµÄ°æ±¾ £¬IntelliJ IDEµÄÍêÕûÐÞ¸´°æ±¾Áбí°üÂÞ£º

Aqua£º2024.1.2

CLion£º2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2

DataGrip£º2024.1.4

DataSpell£º2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2

GoLand£º2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3

IntelliJ IDEA£º2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3

MPS£º2023.2.1, 2023.3.1, 2024.1 EAP2

PhpStorm£º2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3

PyCharm£º2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2

Rider£º2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3

RubyMine£º2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4

RustRover£º2024.1.1

WebStorm£º2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4

ÏÂÔØÁ´½Ó£º

https://www.jetbrains.com/

3.2 ÁÙʱ´ëÊ©

½¨Òé¸üе½IDEµÄ×îа汾¡£

´ËÍâ £¬Èç¹ûÔÚ IDEÖÐʹÓà GitHub À­È¡ÇëÇó¹¦Ð§ £¬½¨ÒéÈ¡Ïû²å¼þÕýÔÚʹÓõÄÈκΠGitHubÁîÅÆ¡£¼øÓڸòå¼þ¿ÉÒÔʹÓà OAuth ¼¯³É»ò¸öÈË·ÃÎÊÁîÅÆ (PAT) £¬Çë¼ì²éÁ½Õß²¢Æ¾¾ÝÐèҪȡÏû£º

OAuth ¼¯³ÉÉèÖãº×ªµ½Ó¦Ó÷¨Ê½¡ú ÊÚȨµÄ OAuth Ó¦Ó÷¨Ê½²¢È¡ÏûJetBrains IDE ¼¯³ÉÓ¦Ó÷¨Ê½µÄ·ÃÎÊȨÏÞ¡£

¸öÈË·ÃÎÊÁîÅÆÉèÖ㺽øÈëTokensÒ³Ãæ £¬É¾³ýΪ²å¼þ·¢±íµÄÁîÅÆ¡£Ä¬ÈÏÁîÅÆÃû³ÆÎªIntelliJ IDEA GitHub integration plugin £¬Ò²¿ÉÒÔʹÓÃ×Ô½ç˵Ãû³Æ¡£

×¢Òâ £¬ÁîÅÆ±»È¡Ïûºó £¬ÐèÒªÖØÐÂÉèÖòå¼þ £¬ÒòΪËùÓвå¼þ¹¦Ð§£¨°üÂÞ Git²Ù×÷£©¶¼½«Í£Ö¹ÊÂÇé¡£´ËÍâ £¬ÓÉÓÚ»º½â´ëÊ© £¬¾É°æ±¾JetBrains IDEÖÐµÄ JetBrains GitHub ²å¼þ¿ÉÄÜÎÞ·¨ÔÙ°´Ô¤ÆÚÊÂÇé¡£

3.3 ͨÓý¨Òé

l  ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡ £¬¼õÉÙϵͳ©¶´ £¬ÌáÉý·þÎñÆ÷µÄÄþ¾²ÐÔ¡£

l  ¼ÓǿϵͳºÍÍøÂçµÄ·ÃÎÊ¿ØÖÆ £¬Ð޸ķÀ»ðǽ¼ÆÄ± £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ £¬¼õÉÙ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬¼õÉÙ¹¥»÷Ãæ¡£

l  ʹÓÃÆóÒµ¼¶Äþ¾²²úÎï £¬ÌáÉýÆóÒµµÄÍøÂçÄþ¾²ÐÔÄÜ¡£

l  ¼ÓǿϵͳÓû§ºÍȨÏÞ¹ÜÀí £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬Óû§ºÍÈí¼þȨÏÞÓ¦±£³ÖÔÚ×îµÍÏÞ¶È¡£

l  ÆôÓÃÇ¿ÃÜÂë¼ÆÄ±²¢ÉèÖÃΪ¶¨ÆÚÐ޸ġ£

3.4 ²Î¿¼Á´½Ó

https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/

https://www.bleepingcomputer.com/news/security/jetbrains-warns-of-intellij-ide-bug-exposing-github-access-tokens/

 


ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-06-13

Ê×´ÎÐû²¼

 

 

Îå¡¢¸½Â¼

5.1 ¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏà £¬¹«Ë¾Ô±¹¤6000ÓàÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

5.2 ¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸ö©¶´Í¨¸æºÍ·çÏÕÔ¤¾¯ £¬ÎÒÃǽ«Á¬Ðø¸ú×ÙÈ«Çò×îеÄÍøÂçÄþ¾²Ê¼þºÍ©¶´ £¬ÎªÆóÒµµÄÐÅÏ¢Äþ¾²±£¼Ý»¤º½¡£

¹Ø×¢ÎÒÃÇ£º

image.png