CVE-2022-29035

LOW

JetBrains Ktor Native <2.0.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

Scores

CVSS v3 3.3
EPSS 0.0000
EPSS Percentile 0.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-330
Status published
Products (1)
jetbrains/ktor < 2.0.0
Published Apr 11, 2022
Tracked Since Feb 18, 2026