CVE-2023-45612
CRITICAL 9.8EPSS 0.6%
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - EPSS
- 0.60% chance of exploitation in the next 30 days, 46th percentile
- Published
- 2023-10-09
- Updated
- 2024-09-19
Proof-of-concept exploits (8)
- aecelen/ktor-xxe-poc
- clemfavre/cve-2023-45612_exploit
- infernosalex/CVE-2023-45612-PoC
- ksaweryr/CVE-2023-45612-PoC
- razvanclaudiu/ktor-xxe-poc
- seraphimi/ktor-xxe
- stefan-500/ktor-cve-2023-45612-poc
- Hotmansifu/Internship_Ktor_POC