First published: Wed Oct 02 2019(Updated: )
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Ktor | <=1.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12736 is critical.
CVE-2019-12736 affects JetBrains Ktor framework before version 1.2.0-rc.
The vulnerability description of CVE-2019-12736 is that JetBrains Ktor framework before version 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
The command injection vulnerability in CVE-2019-12736 can be exploited by providing a malicious username that includes arbitrary commands.
Yes, the fix for CVE-2019-12736 is to upgrade JetBrains Ktor framework to version 1.2.0-rc or later.