VYPR
Critical severity9.8NVD Advisory· Published Oct 2, 2019· Updated Jun 17, 2026

CVE-2019-12736

CVE-2019-12736

Description

JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jetbrains/Ktor2 versions
    cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:*range: <=1.1.5
    • (no CPE)range: <1.2.0-rc
  • JetBrains/Ktor frameworkdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.