First published: Wed Jul 03 2019(Updated: )
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Kotlin | <1.3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2019-10103.
JetBrains Kotlin versions up to and including 1.3.30 are affected.
CVE-2019-10103 has a severity level of 8.1 (high).
This vulnerability can be exploited by performing a Man-in-the-Middle (MITM) attack through the resolving Gradle artifacts using an http connection in JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template.
To fix CVE-2019-10103, update your Kotlin plugin to version 1.3.30 or higher.