JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Link | Tags |
---|---|
https://blog.jetbrains.com/blog/2019/09/26/jetbrains-security-bulletin-q2-2019/ | vendor advisory |