4 ms·
The issue is JetBrains was trying to avoid having the issues disclosed, or at least significantly delay it. They would have been communicated an explicit timeli
by bitexploder 3y ago
The issue is JetBrains was trying to avoid having the issues disclosed, or at least significantly delay it. They would have been communicated an explicit timeline and Rapid7s entire process up front. Rapid7 would have let them patch and released the vulnerability details on a generous timeline if JetBrains had continued to communicate with Rapid7. The reason Rapid7 is doing this is because there are so many companies out there that will ghost you and ignore that your firm exists trying to delay the release of your vulns indefinitely. I have released vulns at my company and coordinated dozens of them. Before coordinated disclosure was a thing it was the wild west and companies often did shady things expecting they could muscle or ignore security researchers.