CVE-2019-10102: High severity kotlin vulnerability
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-10102.
What is the severity of CVE-2019-10102?
CVE-2019-10102 has a severity rating of 8.1 (high).
What is the affected software?
The affected software includes JetBrains Kotlin versions up to 1.3.30 and JetBrains Ktor versions up to 1.1.0.
How can I fix CVE-2019-10102?
To fix CVE-2019-10102, update your Kotlin plugin to version 1.3.30 or higher.
Where can I find more information about CVE-2019-10102?
You can find more information about CVE-2019-10102 in the following references: https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/ and https://security.netapp.com/advisory/ntap-20230818-0012/