MITM Vulnerability in JetBrains IntelliJ IDEA Kotlin Template
CVE-2019-10103

8.1HIGH

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
3 July 2019

Summary

A security issue exists in JetBrains IntelliJ IDEA when projects are created using the Kotlin (JS Client/JVM Server) IDE Template. This vulnerability arises from the resolution of Gradle artifacts over HTTP connections, which exposes the potential for Man-in-the-Middle (MITM) attacks. By exploiting this flaw, attackers could intercept and manipulate the communication between the client and server, leading to unauthorized access and manipulation of data. To mitigate this risk, users should upgrade to Kotlin plugin version 1.3.30 or later, where this issue has been addressed.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.