CVE-2019-10102

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
03/07/2019
Last modified:
18/08/2023

Description

JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jetbrains:kotlin:*:*:*:*:*:*:*:* 1.3.30 (excluding)
cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:* 1.1.0 (excluding)