Comment on IntelliJ GitHub Plugin leaking credentialsComments−orf2yWhat is the actual vulnerability? The post is super light on details.−lostmsu2ySounds like they added token to all requests done by the plugin, so when you opened a pull request and linked an image from 3rd party, the 3rd party would receive your token.
Comments
What is the actual vulnerability? The post is super light on details.
Sounds like they added token to all requests done by the plugin, so when you opened a pull request and linked an image from 3rd party, the 3rd party would receive your token.