top | item 39604011

(no title)

cp9 | 2 years ago

so rapid7 is mad that jetbrains fixed the vulns they reported? isn't that the point of reporting vulnerabilities? why is rapid7 threatening to release the details in 24 hours?

discuss

order

ziddoap|2 years ago

>so rapid7 is mad that jetbrains fixed the vulns they reported?

No. They are mad that they vulnerabilities were _silently_ fixed.

hiatus|2 years ago

Where does the article say that? I see:

> Rapid7 says it reported the two TeamCity vulnerabilities in mid-February, claiming JetBrains soon after suggested releasing patches for the flaws before publicly disclosing them.

So JetBrains wanted to have a patch ready before disclosing the vulnerability publicly. It seems they were working on it and were working with Rapid7. I am struggling to think how it would be better for users if an unpatched vulnerability is released before a patch is available. What's the thinking here, that users will take additional precautions to secure the application while they wait for a patch?