[HN Gopher] IntelliJ GitHub Plugin leaking credentials
___________________________________________________________________
IntelliJ GitHub Plugin leaking credentials
Author : jonahss
Score : 86 points
Date : 2024-06-13 16:34 UTC (6 hours ago)
(HTM) web link (blog.jetbrains.com)
(TXT) w3m dump (blog.jetbrains.com)
| that_guy_iain wrote:
| This is the second time today I've seen this but it is dated the
| 10th how come it's taken everyone so long to notice?
| refulgentis wrote:
| I don't understand what you mean: a blog post was published on
| the 10th, you saw a link to it twice today, so "everyone" took
| "so long to notice"?
|
| I'm teasing, it's just a surprisingly increasing fallacy I see:
| "Why is the rate at which I saw things not the rate I expect?
| What did They mean by this?"
| stuff4ben wrote:
| Good idea to rotate your tokens on a regular basis, but in this
| case, go ahead and do it now (if you use this tool and plugin)
| Merad wrote:
| It seems like GitHub is rejecting requests from affected IDE
| versions. We discovered this yesterday because PR integration was
| not working even though the GitHub login/token was correct. Issue
| resolved by upgrading the IDE to the latest version.
| mattjaynes wrote:
| I have a client who was using JetBrains' TeamCity CI product. Was
| a clown show of vulnerabilities that allowed attackers access to
| internals.
|
| Do not use their products. If you must for some reason, be sure
| you subscribe to critical CVEs of the products you are using and
| update them _immediately_ and rotate your credentials. Ideally
| re-install on a fresh server. Never have the service available
| via the public web, it will be hacked - only use their products
| behind a VPN.
|
| https://blog.jetbrains.com/teamcity/2024/02/critical-securit...
| https://blog.jetbrains.com/teamcity/2024/03/additional-criti...
| rf15 wrote:
| Their plugins are a (very) mixed bag, but saying to not use
| their products is a bit too alarmist if you ask me - the
| baseline IDE is doing fairly well, and teamcity and doing your
| GitHub-specific PR-stuff from within intelliJ is kind of niche
| overall I would assume (I've never used either, only the stock
| git client they have)
| mattjaynes wrote:
| That's fair. I have limited experience with the rest of their
| offerings. They only came onto my radar because of regular
| critical CVEs that needed urgent fixing. The communication
| from the company had no hint of apology - just "hey, better
| fix this before your server is p0wned" - which did not seem
| like they were to be taken seriously.
| orf wrote:
| What is the actual vulnerability? The post is super light on
| details.
| lostmsu wrote:
| Sounds like they added token to all requests done by the
| plugin, so when you opened a pull request and linked an image
| from 3rd party, the 3rd party would receive your token.
___________________________________________________________________
(page generated 2024-06-13 23:01 UTC)