CVE-2019-12736: Command Injection
Published Oct 2, 2019
·Updated
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
Affected Software
1 affected component
JetBrains Ktor<=1.1.5
Event History
Oct 2, 2019
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12736?
The severity of CVE-2019-12736 is critical.
2
How does CVE-2019-12736 affect JetBrains Ktor framework?
CVE-2019-12736 affects JetBrains Ktor framework before version 1.2.0-rc.
3
What is the vulnerability description of CVE-2019-12736?
The vulnerability description of CVE-2019-12736 is that JetBrains Ktor framework before version 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
4
How can the command injection vulnerability in CVE-2019-12736 be exploited?
The command injection vulnerability in CVE-2019-12736 can be exploited by providing a malicious username that includes arbitrary commands.
5
Is there a fix available for CVE-2019-12736?
Yes, the fix for CVE-2019-12736 is to upgrade JetBrains Ktor framework to version 1.2.0-rc or later.