In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://twitter.com/_ruby/status/1234457530790600704 | third party advisory exploit |
https://gist.github.com/rubyroobs/5d273895512df5b86d5e7e1a703c8028 | product |
https://blog.jetbrains.com/blog/2020/04/22/jetbrains-security-bulletin-q1-2020/ | vendor advisory |