[HN Gopher] IntelliJ GitHub Plugin leaking credentials
       ___________________________________________________________________
        
       IntelliJ GitHub Plugin leaking credentials
        
       Author : jonahss
       Score  : 86 points
       Date   : 2024-06-13 16:34 UTC (6 hours ago)
        
 (HTM) web link (blog.jetbrains.com)
 (TXT) w3m dump (blog.jetbrains.com)
        
       | that_guy_iain wrote:
       | This is the second time today I've seen this but it is dated the
       | 10th how come it's taken everyone so long to notice?
        
         | refulgentis wrote:
         | I don't understand what you mean: a blog post was published on
         | the 10th, you saw a link to it twice today, so "everyone" took
         | "so long to notice"?
         | 
         | I'm teasing, it's just a surprisingly increasing fallacy I see:
         | "Why is the rate at which I saw things not the rate I expect?
         | What did They mean by this?"
        
       | stuff4ben wrote:
       | Good idea to rotate your tokens on a regular basis, but in this
       | case, go ahead and do it now (if you use this tool and plugin)
        
       | Merad wrote:
       | It seems like GitHub is rejecting requests from affected IDE
       | versions. We discovered this yesterday because PR integration was
       | not working even though the GitHub login/token was correct. Issue
       | resolved by upgrading the IDE to the latest version.
        
       | mattjaynes wrote:
       | I have a client who was using JetBrains' TeamCity CI product. Was
       | a clown show of vulnerabilities that allowed attackers access to
       | internals.
       | 
       | Do not use their products. If you must for some reason, be sure
       | you subscribe to critical CVEs of the products you are using and
       | update them _immediately_ and rotate your credentials. Ideally
       | re-install on a fresh server. Never have the service available
       | via the public web, it will be hacked - only use their products
       | behind a VPN.
       | 
       | https://blog.jetbrains.com/teamcity/2024/02/critical-securit...
       | https://blog.jetbrains.com/teamcity/2024/03/additional-criti...
        
         | rf15 wrote:
         | Their plugins are a (very) mixed bag, but saying to not use
         | their products is a bit too alarmist if you ask me - the
         | baseline IDE is doing fairly well, and teamcity and doing your
         | GitHub-specific PR-stuff from within intelliJ is kind of niche
         | overall I would assume (I've never used either, only the stock
         | git client they have)
        
           | mattjaynes wrote:
           | That's fair. I have limited experience with the rest of their
           | offerings. They only came onto my radar because of regular
           | critical CVEs that needed urgent fixing. The communication
           | from the company had no hint of apology - just "hey, better
           | fix this before your server is p0wned" - which did not seem
           | like they were to be taken seriously.
        
       | orf wrote:
       | What is the actual vulnerability? The post is super light on
       | details.
        
         | lostmsu wrote:
         | Sounds like they added token to all requests done by the
         | plugin, so when you opened a pull request and linked an image
         | from 3rd party, the 3rd party would receive your token.
        
       ___________________________________________________________________
       (page generated 2024-06-13 23:01 UTC)