CVE-2023-45612: XEE
Published Oct 9, 2023
·Updated
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
Affected Software
1 affected component
JetBrains Ktor<2.3.5
Remediation
Patch Available
Event History
Oct 9, 2023
CVE Published
via MITRE·10:20 AM
Data Sourced
via MITRE·10:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-45612.
2
What is the severity of CVE-2023-45612?
The severity of CVE-2023-45612 is critical.
3
Which software is affected by CVE-2023-45612?
JetBrains Ktor version up to 2.3.5 is affected by CVE-2023-45612.
4
What is the vulnerability in JetBrains Ktor?
The default configuration of ContentNegotiation with XML format in JetBrains Ktor before 2.3.5 was vulnerable to XXE.
5
How can I fix CVE-2023-45612?
To fix CVE-2023-45612, update JetBrains Ktor to version 2.3.5 or later.