Security update for IntelliJ-based IDEs v2016.1 and older versions
blog.jetbrains.com
blog.jetbrains.com
WebStorm 11.0.4
Build #WS-143.2370, built on April 29, 2016
"Check for Update" tells me I have the latest version.However the FAQ (http://blog.jetbrains.com/blog/2016/05/11/security-update-fo...) says:
"All updates published after May 10th contain the security update."
Which would mean that a version built "April 29, 2016" is vulnerable?Also the linked download page (https://confluence.jetbrains.com/display/WI/Previous+WebStor...) says:
"Latest version: WebStorm 11.0.5 (build 143.2370, May, 11 2016)"
That is, the version number and date are different from what I have, but the build number is the same?!Maybe it's too late in the day for me to think straight, but somethings wrong here. What product versions are safe?
https://intellij-support.jetbrains.com/hc/en-us/articles/208...
Please see if that works.
We've done our best to address the issue, provide the fixes for current versions as well as back-port it up to 3 years for all products running on the platform. In any case we apologise and have learned from this and will improve.
I'm glad to see proper credit given to Jordan for finding the flaw. Maybe I'm a cynic, but I'm glad that this was an open process and not a one line blog post about a critical security update. Keep up the great work.
They also gave me diffs against intellij-community master so I could verify their fixes were sound, and they were generally receptive to my feedback.