Skip to content

Comment on IntelliJ GitHub Plugin leaking credentials

Comments

What is the actual vulnerability? The post is super light on details.

Sounds like they added token to all requests done by the plugin, so when you opened a pull request and linked an image from 3rd party, the 3rd party would receive your token.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.