First published: Wed Jul 03 2019(Updated: )
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Kotlin | <1.3.30 | |
JetBrains Ktor | <1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-10102.
CVE-2019-10102 has a severity rating of 8.1 (high).
The affected software includes JetBrains Kotlin versions up to 1.3.30 and JetBrains Ktor versions up to 1.1.0.
To fix CVE-2019-10102, update your Kotlin plugin to version 1.3.30 or higher.
You can find more information about CVE-2019-10102 in the following references: https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/ and https://security.netapp.com/advisory/ntap-20230818-0012/