In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.jetbrains.com/privacy-security/issues-fixed/ | vendor advisory |