JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (Fixed)
rapid7.com
rapid7.com
Is this a failure on JetBrain's part to acknowledge the issue and properly give credit for discovering the CVE?
(Disclosure: I know some of the folk on the Rapid7 side, so I'm perhaps biased towards their interpretation of events)
There's more to the story that Rapid7 didn't want to air publicly, and none of it is good for JetBrains.
> it's super inappropriate to lie to researchers who disclosed this to you responsibly about what your plans are.
That would be super inappropriate, yes! But Rapid7 hasn't alleged that publicly that I've seen. All I have seen so far is researchers alluding to bad behaviour and deception, and no concrete or falsifiable accusations.
Cutting Rapid7 out of the disclosure is definitely poor form, but that's a far cry from lies and deception. As a not-totally-disinterested outside observer (using JetBrains' IDE products but not TeamCity) I definitely want to know if they are behaving badly so I can factor that into my future plans. But without a concrete falsifiable accusation it reads to me like butthurt on the part of the researchers involved.
If the contention is when to release details, then should agree on UTC for all parties, with appropriate time precision. Anything else is adding obscurity to an already difficult-to-follow plot.