Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Ktor
(Jetbrains)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 20 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-08-12 | CVE-2022-38180 | In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases | Ktor | 6.5 | ||
2023-04-24 | CVE-2022-48476 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | Ktor | 7.5 | ||
2023-06-01 | CVE-2023-34339 | In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message | Ktor | 3.3 | ||
2023-10-09 | CVE-2023-45612 | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE | Ktor | 9.8 | ||
2023-10-09 | CVE-2023-45613 | In JetBrains Ktor before 2.3.5 server certificates were not verified | Ktor | 9.1 | ||
2019-07-03 | CVE-2019-10102 | JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30. | Kotlin, Ktor | 8.1 | ||
2019-12-26 | CVE-2019-19389 | JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. | Ktor | N/A | ||
2019-12-10 | CVE-2019-19703 | In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. | Ktor | N/A | ||
2019-10-02 | CVE-2019-12737 | UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. | Ktor | N/A | ||
2019-10-02 | CVE-2019-12736 | JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection. | Ktor | N/A |