CVE-2022-24329
published 2022-02-25CVE-2022-24329: In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
2.18%
80.3th percentile
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kotlin | — | — |
| jetbrains | kotlin | < 1.6.0 | 1.6.0 |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | communications_pricing_design_center | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Insurance Applications Risk Matrix: EWPS (JetBrains Kotlin) — CVE-2022-24329
vendor_oracle·2025-10-15·CVSS 5.3
CVE-2022-24329 [MEDIUM] Oracle Oracle Insurance Applications Risk Matrix: EWPS (JetBrains Kotlin) — CVE-2022-24329
Oracle Oracle Insurance Applications Risk Matrix: EWPS (JetBrains Kotlin) vulnerability
CVE: CVE-2022-24329
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (JetBrains Kotlin) — CVE-2022-24329
vendor_oracle·2024-04-15·CVSS 5.3
CVE-2022-24329 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (JetBrains Kotlin) — CVE-2022-24329
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (JetBrains Kotlin) vulnerability
CVE: CVE-2022-24329
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (JetBrains Kotlin) — CVE-2022-24329
vendor_oracle·2023-10-15·CVSS 5.3
CVE-2022-24329 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install/Upgrade (JetBrains Kotlin) — CVE-2022-24329
Oracle Oracle Communications Risk Matrix: Install/Upgrade (JetBrains Kotlin) vulnerability
CVE: CVE-2022-24329
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Majel Mobile Service (Kotlin) — CVE-2022-24329
vendor_oracle·2023-01-15·CVSS 5.3
CVE-2022-24329 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Majel Mobile Service (Kotlin) — CVE-2022-24329
Oracle Oracle Fusion Middleware Risk Matrix: Majel Mobile Service (Kotlin) vulnerability
CVE: CVE-2022-24329
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: BSF (JetBrains Kotlin) — CVE-2022-24329
vendor_oracle·2022-07-15·CVSS 5.3
CVE-2022-24329 [MEDIUM] Oracle Oracle Communications Risk Matrix: BSF (JetBrains Kotlin) — CVE-2022-24329
Oracle Oracle Communications Risk Matrix: BSF (JetBrains Kotlin) vulnerability
CVE: CVE-2022-24329
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST Services Manager (Kotlin) — CVE-2022-24329
vendor_oracle·2022-04-15·CVSS 5.3
CVE-2022-24329 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: REST Services Manager (Kotlin) — CVE-2022-24329
Oracle Oracle Communications Applications Risk Matrix: REST Services Manager (Kotlin) vulnerability
CVE: CVE-2022-24329
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects
vendor_redhat·2022-02-25·CVSS 5.3
CVE-2022-24329 [MEDIUM] CWE-667 kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects
kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Package: kotlin (A-MQ Clients 2) - Not affected
Package: kotlin (Red Hat AMQ Broker 7) - Not affected
Package: kotlin (Red Hat build of Apicurio Registry 2) - Not affected
Package: kotlin (Red Hat build of Debezium 1) - Not affected
Package: kotlin (Red Hat build of Quarkus) - Not affected
Package: kotlin (Red Hat Data Grid 8) - Not affected
Package: kotlin (Red Hat Fuse 7) - Not affected
Package: kotlin (Red Hat Integration Camel K 1) - Not affected
Package: kotlin (Red Hat Integration Camel Quarkus 1) - Not affected
Package: kotlin (Red Hat Integration Data Virtualisation Operator) - Not affect
Debian
CVE-2022-24329: kotlin - In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for M...
vendor_debian·2022·CVSS 5.3
CVE-2022-24329 [MEDIUM] CVE-2022-24329: kotlin - In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for M...
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Improper Locking in JetBrains Kotlin
ghsa·2022-02-26
CVE-2022-24329 [MEDIUM] CWE-667 Improper Locking in JetBrains Kotlin
Improper Locking in JetBrains Kotlin
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
OSV
Improper Locking in JetBrains Kotlin
osv·2022-02-26
CVE-2022-24329 [MEDIUM] Improper Locking in JetBrains Kotlin
Improper Locking in JetBrains Kotlin
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
OSV
CVE-2022-24329: In JetBrains Kotlin before 1
osv·2022-02-25·CVSS 5.3
CVE-2022-24329 [MEDIUM] CVE-2022-24329: In JetBrains Kotlin before 1
In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://blog.jetbrains.comhttps://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://blog.jetbrains.comhttps://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-02-25
Published