CVE-2020-11685 (NVD)

2020-04-22

In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

Products Goland
Type Missing Encryption of Sensitive Data (CWE-311)
First patch - None (likely due to unavailable code)
Links https://blog.jetbrains.com/blog/2020/04/22/jetbrains-security-bulletin-q1-2020/