Product:

Ktor

(Jetbrains)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 20
Date Id Summary Products Score Patch Annotated
2022-08-12 CVE-2022-38180 In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases Ktor 6.5
2023-04-24 CVE-2022-48476 In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible Ktor 7.5
2023-06-01 CVE-2023-34339 In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message Ktor 3.3
2023-10-09 CVE-2023-45612 In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE Ktor 9.8
2023-10-09 CVE-2023-45613 In JetBrains Ktor before 2.3.5 server certificates were not verified Ktor 9.1
2019-07-03 CVE-2019-10102 JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30. Kotlin, Ktor 8.1
2019-12-26 CVE-2019-19389 JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. Ktor N/A
2019-12-10 CVE-2019-19703 In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. Ktor N/A
2019-10-02 CVE-2019-12737 UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. Ktor N/A
2019-10-02 CVE-2019-12736 JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection. Ktor N/A