JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HJetbrains Kotlin
APPJetbrains< 1.3.30Jetbrains Ktor
APPJetbrains< 1.1.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Powiązane podatności
CVE-2019-12736CRITICAL9.8PL ✓ten sam produkt
JetBrains Ktor: command injection w obsłudze protokołu LDAP
CVE-2023-45612HIGH8.6ten sam produkt
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to X...
CVE-2022-48476HIGH7.5ten sam produkt
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2022-29930HIGH8.7ten sam produkt
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor v...
CVE-2021-43203HIGH7.5ten sam produkt
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented imp...