Lucene search

K
cveJetBrainsCVE-2023-45613
HistoryOct 09, 2023 - 11:15 a.m.

CVE-2023-45613

2023-10-0911:15:11
CWE-295
JetBrains
web.nvd.nist.gov
33
jetbrains
ktor
cve-2023-45613
server certificate
verification
nvd

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

29.3%

In JetBrains Ktor before 2.3.5 server certificates were not verified

Affected configurations

Nvd
Node
jetbrainsktorRange<2.3.5
VendorProductVersionCPE
jetbrainsktor*cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "JetBrains",
    "product": "Ktor",
    "versions": [
      {
        "version": "0",
        "status": "affected",
        "lessThan": "2.3.5",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

29.3%