In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NJetbrains Ktor
APPJetbrains< 2.3.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XXE
Related vulnerabilities
CVE-2019-12736CRITICAL9.8PL ✓same product
JetBrains Ktor: command injection w obsłudze protokołu LDAP
CVE-2022-48476HIGH7.5same product
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2022-29930HIGH8.7same product
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor v...
CVE-2021-43203HIGH7.5same product
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented imp...
CVE-2019-10102HIGH8.1same product
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifact...