CVE-2019-10102
Summary
| CVE | CVE-2019-10102 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-03 20:15:00 UTC |
| Updated | 2023-08-18 14:15:00 UTC |
| Description | JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| July 2023 JetBrains Kotlin Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| JetBrains Security Bulletin Q1 2019 | JetBrains News | MISC | blog.jetbrains.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.