CVE-2019-10102

JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jetbrains:kotlin:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:*

History

18 Aug 2023, 14:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230818-0012/ -

Information

Published : 2019-07-03 20:15

Updated : 2024-02-04 20:20


NVD link : CVE-2019-10102

Mitre link : CVE-2019-10102

CVE.ORG link : CVE-2019-10102


JSON object : View

Products Affected

jetbrains

  • ktor
  • kotlin
CWE
CWE-319

Cleartext Transmission of Sensitive Information