Input validation error in Kotlin Ktor - CVE-2019-12736

 

Input validation error in Kotlin Ktor - CVE-2019-12736

Published: November 5, 2019


Vulnerability identifier: #VU22508
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12736
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary commands on the target system.

The vulnerability exists due to the affected software does not sanitize the username provided by the user for the LDAP protocol. A remote attacker can inject arbitrary commands on the target system.


Affected software

Kotlin Ktor

How to mitigate CVE-2019-12736

Install updates from vendor's website.

Kotlin Ktor - addressed in versions 1.2.0 rc, 1.2.0

External References

Related Security Bulletins