CVE-2019-10101
published 2019-07-03CVE-2019-10101: JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
PriorityP342high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.62%
73.4th percentile
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kotlin | — | — |
| jetbrains | kotlin | < 1.3.30 | 1.3.30 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-10101: kotlin - JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http c...
vendor_debian·2019·CVSS 8.1
CVE-2019-10101 [HIGH] CVE-2019-10101: kotlin - JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http c...
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-8fr9-3mxv-p3vf: JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2019-10103 [HIGH] CWE-311 GHSA-8fr9-3mxv-p3vf: JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.
GHSA
GHSA-p2g6-rgr3-jm3m: JetBrains Kotlin versions before 1
ghsa_unreviewed·2022-05-24
CVE-2019-10101 [MEDIUM] CWE-319 GHSA-p2g6-rgr3-jm3m: JetBrains Kotlin versions before 1
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
OSV
CVE-2019-10103: JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection
osv·2019-07-03·CVSS 8.1
CVE-2019-10103 [HIGH] CVE-2019-10103: JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection
JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/https://medium.com/bugbountywriteup/want-to-take-over-the-java-ecosystem-all-you-need-is-a-mitm-1fc329d898fbhttps://security.netapp.com/advisory/ntap-20230818-0012/https://blog.jetbrains.com/blog/2019/06/19/jetbrains-security-bulletin-q1-2019/https://medium.com/bugbountywriteup/want-to-take-over-the-java-ecosystem-all-you-need-is-a-mitm-1fc329d898fbhttps://security.netapp.com/advisory/ntap-20230818-0012/
2019-07-03
Published