JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
References
Link | Resource |
---|---|
https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-07-03 13:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-10102
Mitre link : CVE-2019-10102
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
jetbrains
- kotlin
- ktor