Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Filtered by product Ktor
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25761 1 Jetbrains 1 Ktor 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
CVE-2022-29930 1 Jetbrains 1 Ktor 2022-06-24 4.0 MEDIUM 4.9 MEDIUM
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
CVE-2021-25762 1 Jetbrains 1 Ktor 2021-02-08 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
CVE-2021-25763 1 Jetbrains 1 Ktor 2021-02-05 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
CVE-2020-26129 1 Jetbrains 1 Ktor 2020-12-01 6.4 MEDIUM 6.5 MEDIUM
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
CVE-2019-19389 1 Jetbrains 1 Ktor 2020-08-24 3.5 LOW 5.4 MEDIUM
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVE-2019-19703 1 Jetbrains 1 Ktor 2019-12-13 5.8 MEDIUM 6.1 MEDIUM
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
CVE-2019-12737 1 Jetbrains 1 Ktor 2019-10-08 5.0 MEDIUM 5.3 MEDIUM
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.