anyone from jetbrains can confirm this? because this is a pretty serious issue
Yes, the author has been working directly with the teams from Jetbrains, Gradle, Spring, etc. to get these issues resolved and the word spread. It should be taken as very serious, and everyone should check their builds for these flaws
Spring just released a tool that might help with patching this issue, though https://spring.io/blog/2019/06/10/announcing-nohttp
There's also that PR in Gradle to make http opt-in: https://github.com/gradle/gradle/pull/9419