Vulnerabilities > Jetbrains > Ktor > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-24 CVE-2022-48476 Path Traversal vulnerability in Jetbrains Ktor
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
network
low complexity
jetbrains CWE-22
7.5
2019-10-02 CVE-2019-12736 Command Injection vulnerability in Jetbrains Ktor
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
network
low complexity
jetbrains CWE-77
7.5
2019-07-03 CVE-2019-10102 Cleartext Transmission of Sensitive Information vulnerability in Jetbrains Kotlin and Ktor
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.
network
high complexity
jetbrains CWE-319
8.1