Input validation error in Kotlin Ktor - CVE-2019-12736
Published: November 5, 2019
Vulnerability identifier: #VU22508
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12736
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary commands on the target system.
The vulnerability exists due to the affected software does not sanitize the username provided by the user for the LDAP protocol. A remote attacker can inject arbitrary commands on the target system.
Affected software
Kotlin Ktor
How to mitigate CVE-2019-12736
Install updates from vendor's website.
Kotlin Ktor - addressed in versions 1.2.0 rc, 1.2.0