First published: Mon Oct 09 2023(Updated: )
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
Credit: security@jetbrains.com security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Ktor | <2.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-45612.
The severity of CVE-2023-45612 is critical.
JetBrains Ktor version up to 2.3.5 is affected by CVE-2023-45612.
The default configuration of ContentNegotiation with XML format in JetBrains Ktor before 2.3.5 was vulnerable to XXE.
To fix CVE-2023-45612, update JetBrains Ktor to version 2.3.5 or later.