Описание
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
Ссылки
- Vendor Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.30 (исключая)
cpe:2.3:a:jetbrains:kotlin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00012
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-319
Связанные уязвимости
CVSS3: 8.1
debian
больше 6 лет назад
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using ...
CVSS3: 8.1
github
больше 3 лет назад
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
EPSS
Процентиль: 1%
0.00012
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-319