IntelliJ GitHub Plugin leaking credentials
blog.jetbrains.com
IntelliJ GitHub Plugin leaking credentials
1–10 of 26 posts
Re: IntelliJ GitHub Plugin leaking credentials
#2Re: IntelliJ GitHub Plugin leaking credentials
#3Re: IntelliJ GitHub Plugin leaking credentials
#4Re: IntelliJ GitHub Plugin leaking credentials
#5This is the second time today I’ve seen this but it is dated the 10th how come it’s taken everyone so long to notice?
I'm teasing, it's just a surprisingly increasing fallacy I see: "Why is the rate at which I saw things not the rate I expect? What did They mean by this?"
Re: IntelliJ GitHub Plugin leaking credentials
#6Re: IntelliJ GitHub Plugin leaking credentials
#7Do not use their products. If you must for some reason, be sure you subscribe to critical CVEs of the products you are using and update them immediately and rotate your credentials. Ideally re-install on a fresh server. Never have the service available via the public web, it will be hacked - only use their products behind a VPN.
https://blog.jetbrains.com/teamcity/2024/02/critical-securit... https://blog.jetbrains.com/teamcity/2024/03/additional-criti...
Re: IntelliJ GitHub Plugin leaking credentials
#8I have a client who was using JetBrains' TeamCity CI product. Was a clown show of vulnerabilities that allowed attackers access to internals. Do not use their products. If you must for some reason, be sure you subscribe to critical CVEs of the products you are using and update them immediately and rotate your credentials. Ideally re-install on a fresh server. Never have the service available via the public web, it wi…