CVE-2019-10103

Severity CVSS v4.0:
Pending analysis
Type:
CWE-311 Missing Encryption of Sensitive Data
Publication date:
03/07/2019
Last modified:
18/08/2023

Description

JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jetbrains:kotlin:*:*:*:*:*:*:*:* 1.3.30 (excluding)