Showing 10 vulnerabilities on this page for Ktor

Signals CISA KEV Ransomware Nuclei
JetBrains vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible

CWE-444Mar 12, 2025
CVSS5.3v3.1EPSS0.318%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

JetBrains Ktor information disclosure

In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

CWE-524Oct 17, 2024
CVSS5.3v3.1EPSS0.352%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains Ktor before 2.3.5 server certificates were not verified

CWE-295Oct 9, 2023
CVSS6.8v3.1EPSS0.298%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

CWE-611Oct 9, 2023
CVSS8.6v3.1EPSS0.595%PoCs7SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message

CWE-209Jun 1, 2023
CVSS3.3v3.1EPSS0.21%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible

CWE-22CWE-35Apr 24, 2023
CVSS7.5v3.1EPSS0.751%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication provider

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

CWE-287Aug 12, 2022
CVSS5.3v3.1EPSS0.701%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

JetBrains Ktor before 2.1.0 was vulnerable to a Reflect File Download attack

JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack

CWE-184CWE-697Aug 12, 2022
CVSS4.7v3.1EPSS0.461%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

CWE-330CWE-342May 12, 2022
CVSS8.7v3.1EPSS0.855%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

CWE-330Apr 11, 2022
CVSS3.3v3.1EPSS0.611%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX