First published: Fri Feb 25 2022(Updated: )
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Kotlin | <1.6.0 | |
Oracle Communications Cloud Native Core Binding Support Function | =22.1.3 | |
Oracle Communications Pricing Design Center | =12.0.0.4 | |
Oracle Communications Pricing Design Center | =12.0.0.5 | |
maven/org.jetbrains.kotlin:kotlin-stdlib | <=1.5.32 | 1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24329 is a vulnerability in JetBrains Kotlin before version 1.6.0 that allows an attacker to compromise multiplatform Gradle projects by bypassing dependency locks.
CVE-2022-24329 has a severity rating of 5.3 (medium).
JetBrains Kotlin before version 1.6.0 is affected by CVE-2022-24329, as well as Oracle Communications Cloud Native Core Binding Support Function version 22.1.3, Oracle Communications Pricing Design Center versions 12.0.0.4 and 12.0.0.5.
To fix CVE-2022-24329, update JetBrains Kotlin to version 1.6.0 or later, Oracle Communications Cloud Native Core Binding Support Function to a version later than 22.1.3, or Oracle Communications Pricing Design Center to a version later than 12.0.0.5.
You can find more information about CVE-2022-24329 in the JetBrains Security Bulletin for Q4 2021 (https://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/) and the Oracle Security Alerts for CPU Apr 2022 (https://www.oracle.com/security-alerts/cpuapr2022.html).