Tag: JetBrains

JetBrains warns of critical TeamCity remote code execution flaw
News

JetBrains warns of critical TeamCity remote code execution flaw

A serious authentication bypass issue affecting TeamCity On-Premises that might be used to accomplish remote code execution is being alerted by JetBrains. An attacker with HTTPS access to a TeamCity server can use the security flaw, known as CVE-2026-63077, to circumvent authentication through the agent polling protocol and run arbitrary operating system commands with the server process's capabilities. JetBrains cautions in the advisory that all versions of TeamCity On-Premises are impacted, however TeamCity Cloud users are not obliged to take any action because the needed precautions have already been taken. Software development, testing, and deployment are all done with TeamCity, a commercial continuous integration and continuous delivery (CI/CD) server. According to Daniel Gal...
JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens
News

JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens

Customers of JetBrains' IntelliJ integrated development environment (IDE) apps are advised to repair a major vulnerability that exposes GitHub access tokens. This security vulnerability, tracked as CVE-2024-37051, affects all IntelliJ-based IDEs running 2023.1 or later when the JetBrains GitHub plugin is activated, set up, or in use. Ilya Pleskunin, a security support team lead at JetBrains, stated, "On May 29, 2024, we received an external security report with details of a possible vulnerability that would affect pull requests within the IDE." In particular, access tokens would be exposed to a third-party host if malicious content was included in a pull request for a GitHub project that was managed by IntelliJ-based IDEs read more JetBrains warns of IntelliJ IDE bug exposing Git...