In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://blog.jetbrains.com/blog/2020/04/22/jetbrains-security-bulletin-q1-2020/ | vendor advisory |