JetBrains Vulnerabilities and Affected Products
Vulnerabilities associated with Ktor.
Products
Clear product- TeamCity183 vulnerabilities
- YouTrack62 vulnerabilities
- IntelliJ IDEA49 vulnerabilities
- Hub16 vulnerabilities
- Ktor10 vulnerabilities
- GoLand6 vulnerabilities
- Rider6 vulnerabilities
- Toolbox App6 vulnerabilities
- WebStorm6 vulnerabilities
- PyCharm5 vulnerabilities
- PhpStorm4 vulnerabilities
- Junie3 vulnerabilities
- ReSharper2 vulnerabilities
- RubyMine2 vulnerabilities
- Aqua1 vulnerability
- CLion1 vulnerability
- DataGrip1 vulnerability
- Datalore1 vulnerability
- DataSpell1 vulnerability
- dotTrace1 vulnerability
- ETW Host Service1 vulnerability
- IDE Services1 vulnerability
- intellij_idea1 vulnerability
- JetBrains Gateway1 vulnerability
- Kotlin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-29904MEDIUM | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible CWE-444Mar 12, 2025 | CVSS5.3v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49580MEDIUM | JetBrains Ktor information disclosureIn JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure CWE-524Oct 17, 2024 | CVSS5.3v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45613MEDIUM | In JetBrains Ktor before 2.3.5 server certificates were not verified CWE-295Oct 9, 2023 | CVSS6.8v3.1 | EPSS0.298% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45612HIGH | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE CWE-611Oct 9, 2023 | CVSS8.6v3.1 | EPSS0.595% | PoCs7 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message CWE-209Jun 1, 2023 | CVSS3.3v3.1 | EPSS0.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-48476HIGH | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | CVSS7.5v3.1 | EPSS0.751% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38180MEDIUM | JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication providerIn JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases CWE-287Aug 12, 2022 | CVSS5.3v3.1 | EPSS0.701% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38179MEDIUM | JetBrains Ktor before 2.1.0 was vulnerable to a Reflect File Download attackJetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack | CVSS4.7v3.1 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29930HIGH | SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1. | CVSS8.7v3.1 | EPSS0.855% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations CWE-330Apr 11, 2022 | CVSS3.3v3.1 | EPSS0.611% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |