CVE-2023-45612 is an XML External Entity (XXE) vulnerability in JetBrains Ktor before version 2.3.5. The issue affects the default configuration of the ContentNegotiation feature when XML format is enabled. In vulnerable configurations, XML input is processed in a way that permits external entity resolution, allowing attacker-supplied XML to trigger XXE behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a minimal Kotlin/Gradle Ktor server intentionally configured to demonstrate CVE-2023-45612 (XXE in Ktor < 2.3.5 when using ContentNegotiation with the default xml() serializer). Structure/purpose: - build.gradle.kts / gradle.properties / settings.gradle.kts: pins Ktor 2.3.4 and includes ktor-server-content-negotiation + ktor-serialization-kotlinx-xml, enabling XML deserialization. - src/main/kotlin/Application.kt: installs ContentNegotiation { xml() } with default (vulnerable) XML parser settings and starts Netty engine. - src/main/kotlin/Routing.kt: defines @Serializable Message(message: String) and a POST /message handler that performs call.receive<Message>(); the deserialized message is reflected back in the response ("Message received: ..."). This reflection is what exfiltrates expanded entity content. - src/main/resources/application.yaml: configures server port 8080. - secret_file.txt: sample local file whose contents are intended to be stolen via XXE. Exploit capability: - Remote attacker sends crafted XML with a DOCTYPE and external entity (e.g., SYSTEM "secret_file.txt" or an absolute path) to POST /message with Content-Type: application/xml. - Vulnerable XML parser resolves the external entity during deserialization, populating Message.message with file contents. - Server responds with the expanded content, achieving arbitrary file read (proof-of-concept).
This repository is a proof-of-concept (PoC) for CVE-2023-45612, an XML External Entity (XXE) injection vulnerability in JetBrains Ktor (versions before 2.3.5) when using the ContentNegotiation plugin with the default xml() serializer. The repository contains a minimal Ktor server written in Kotlin, with the main entry point in src/main/kotlin/Application.kt and the vulnerable endpoint defined in src/main/kotlin/Routing.kt. The /message endpoint accepts POST requests with XML payloads, which are deserialized without disabling external entity resolution, allowing attackers to craft XML that reads arbitrary files from the server (demonstrated with secret_file.txt). The README.md provides detailed setup, exploitation, and mitigation instructions. The exploit is network-based, targeting the /message HTTP endpoint, and demonstrates the risk of XXE in improperly configured XML parsers.
This repository is a proof-of-concept (PoC) for exploiting CVE-2023-45612, an XML External Entity (XXE) vulnerability in JetBrains Ktor (v2.3.4 and earlier) when XML ContentNegotiation is enabled with default settings. The repository contains a minimal Ktor application written in Kotlin, with the main logic in 'src/main/kotlin/Application.kt' and 'src/main/kotlin/Routing.kt'. The application exposes a '/xml' POST endpoint that deserializes XML input using a vulnerable configuration, allowing external entities to be resolved. The included payload ('exploit/payloads/xxe-demo-file.xml') demonstrates how an attacker can retrieve the contents of an arbitrary file ('exploit/etc/secret.txt') from the server. The README provides detailed instructions for running the server and reproducing the exploit. The attack vector is network-based, requiring the attacker to send a crafted XML payload to the vulnerable endpoint. The repository structure is typical for a Kotlin/Gradle project, with supporting files for build configuration and demonstration purposes. No detection scripts or fake exploit indicators are present; this is a functional PoC for a real vulnerability.
This repository is a proof-of-concept (PoC) for CVE-2023-45612, an XML External Entity (XXE) vulnerability in JetBrains Ktor (version 2.3.4) when using ContentNegotiation with XML serialization. The repository is structured into two main components: - The 'server/' directory contains a Ktor server application written in Kotlin, configured to be vulnerable to XXE by accepting XML input at the '/foo' endpoint and deserializing it into a Kotlin data class. The server is set up via Docker and exposes port 8080. A file '/lfi_poc.txt' is created in the server container to demonstrate file read via XXE. - The 'client/' directory contains a Python script ('poc.py') that crafts and sends a malicious XML payload to the server's '/foo' endpoint. The payload uses an external entity to attempt to read '/lfi_poc.txt' from the server, demonstrating Local File Inclusion (LFI) via XXE. The exploit demonstrates that, in the default configuration, Ktor's ContentNegotiation with XML serialization is susceptible to XXE, allowing attackers to read arbitrary files from the server. The repository includes Dockerfiles and a docker-compose.yaml for easy setup and reproduction of the vulnerability. The main attack vector is network-based, targeting the HTTP endpoint '/foo' on the vulnerable server. The PoC does not weaponize the exploit beyond demonstrating file read, and is intended for educational and testing purposes.
This repository demonstrates and tests an XXE (XML External Entity) vulnerability in JetBrains Ktor (version 2.2.4) with the ContentNegotiation XML plugin, specifically targeting CVE-2023-45612. The project includes a vulnerable Ktor server implemented in Kotlin (src/main/kotlin/), which exposes a '/xml' endpoint that deserializes XML input without proper XXE protection. The 'poc.py' script is a Python-based proof-of-concept exploit that can send malicious XML payloads to the server to either read arbitrary files (e.g., /etc/passwd, /etc/hostname) or perform SSRF by referencing remote URLs. The repository is structured as a typical Gradle-based Kotlin project, with supporting build files and configuration. The exploit is a working POC, not weaponized, and provides clear instructions for both running the vulnerable server and executing the exploit. No hardcoded IPs or domains are present, but the endpoints '/xml' and example file paths are fingerprintable. The main exploit capability is remote file disclosure and SSRF via XXE injection.
This repository demonstrates a proof-of-concept exploit for CVE-2023-45612, an XML External Entity (XXE) vulnerability in JetBrains Ktor's XML serialization (specifically in version 2.3.4 of 'io.ktor:ktor-serialization-kotlinx-xml'). The project is structured as a Kotlin server application using Ktor, with the main logic in 'server/src/main/kotlin/Main.kt'. The server exposes an HTTP POST endpoint at '/process' that accepts XML input, deserializes it into a 'Person' object, and responds with the 'name' field. The exploit works by submitting a crafted XML file (see 'xml_files/xxe.xml') that defines an external entity referencing a local file ('sensitive_infos.txt'). When processed by the vulnerable server, the entity is expanded, and the file's contents are returned in the HTTP response. The repository includes both a benign XML example and the malicious XXE payload, as well as a README with detailed reproduction steps and mitigation advice. The exploit demonstrates the risk of XXE in improperly configured XML parsers and highlights the importance of using patched library versions.
This repository is a proof-of-concept (POC) for exploiting CVE-2023-45612, an XML External Entity (XXE) vulnerability in JetBrains Ktor (version 2.2.3) when using the xmlutil library for XML deserialization. The project is structured as a Kotlin-based Ktor server application with a single POST endpoint at /student, which deserializes XML input into a StudentData object. The exploit is demonstrated via the included test.py script, which sends both a normal XML request and a malicious XXE payload to the server. The XXE payload attempts to read sensitive files from the server's filesystem (e.g., /etc/passwd or C:\windows\win.ini) and have their contents returned in the HTTP response. The repository includes build files for Gradle, configuration files for Ktor, and logging setup. The main entry points are src/main/kotlin/Application.kt (server) and test.py (exploit client). This POC demonstrates the risk of XXE in improperly configured XML deserialization in Ktor applications.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-45612, a critical XML External Entity (XXE) vulnerability in JetBrains Ktor (before version 2.3.5) when configured with the vulnerable xmlutil library. The main exploit script, CVE-2023-45612.py, is a Python tool that crafts and sends a malicious XML payload to a target Ktor server's XML endpoint (default /xml). The payload leverages XXE to read arbitrary files from the server's filesystem, with the file path specified by the user. The script provides colored output, request/response previews, and connectivity checks. The repository also includes a minimal Ktor server implementation in Kotlin (src/main/kotlin/), which demonstrates both safe and unsafe XML parsing endpoints, including /xml (vulnerable to XXE), /xml-unsafe (explicitly unsafe), and /xml-dont-parse (echoes XML). Supporting files include build scripts, configuration, and documentation. The exploit is operational as a PoC and demonstrates the risk of XXE in misconfigured Ktor applications.
This repository is a proof-of-concept (POC) for CVE-2023-45612, demonstrating an XML External Entity (XXE) vulnerability in a Ktor (Kotlin) web application using the xmlutil 0.86.1 library. The repository contains both the vulnerable server code (Kotlin) and a Python script (xxe_poc.py) to exploit the vulnerability. The server exposes several HTTP endpoints, with /xml, /xml-vulnerable, and /xml-direct being vulnerable to XXE due to improper XML parsing configurations that allow external entity expansion. The /xml-raw endpoint is not vulnerable as it does not parse the XML. The Python script xxe_poc.py constructs a malicious XML payload containing an external entity referencing a file on the server's filesystem. When sent to the /xml endpoint, the server parses and expands the entity, returning the contents of the specified file in the HTTP response. This allows an attacker to read arbitrary files from the server. The repository is structured as a typical Gradle-based Kotlin project, with the main application logic in src/main/kotlin and configuration files in src/main/resources. The exploit is operational as a POC and demonstrates the risk of using vulnerable XML parsing libraries without proper configuration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.