Vulnerability Description
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jetbrains | Kotlin | < 1.3.30 |
Related Weaknesses (CWE)
References
- https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/Vendor Advisory
- https://medium.com/bugbountywriteup/want-to-take-over-the-java-ecosystem-all-youExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230818-0012/
- https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/Vendor Advisory
- https://medium.com/bugbountywriteup/want-to-take-over-the-java-ecosystem-all-youExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230818-0012/
FAQ
What is CVE-2019-10101?
CVE-2019-10101 is a vulnerability with a CVSS score of 8.1 (HIGH). JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
How severe is CVE-2019-10101?
CVE-2019-10101 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10101?
Check the references section above for vendor advisories and patch information. Affected products include: Jetbrains Kotlin.