« Volver al listado

Jetbrains

Jetbrains Ktor: vulnerabilidades y CVE

Jetbrains Ktor tiene 22 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE22
Últimos 12 meses1
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-68762Media (5.9)0.37%—17 ago 2026
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
CVE-2025-29904Media (5.3)0.32%—12 mar 2025
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
CVE-2024-49580Media (5.3)0.35%—17 oct 2024
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
CVE-2023-45613Crítica (9.1)0.30%—9 oct 2023
In JetBrains Ktor before 2.3.5 server certificates were not verified
CVE-2023-45612Crítica (9.8)0.60%—9 oct 2023
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
CVE-2023-34339Baja (3.3)0.21%—1 jun 2023
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
CVE-2022-48476Alta (7.5)0.75%—24 abr 2023
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2022-38180Media (6.5)0.72%—12 ago 2022
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
CVE-2022-38179Media (6.1)0.47%—12 ago 2022
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
CVE-2022-29930Media (4.9)0.88%—12 may 2022
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
CVE-2022-29035Baja (2.7)0.62%—11 abr 2022
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
CVE-2021-43203Alta (7.5)0.86%—9 nov 2021
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
CVE-2021-25763Media (5.3)0.54%—3 feb 2021
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
CVE-2021-25762Media (5.3)0.81%—3 feb 2021
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
CVE-2021-25761Media (5.3)0.54%—3 feb 2021
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
CVE-2020-26129Media (6.5)0.77%—16 nov 2020
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
CVE-2020-5207Alta (7.5)0.76%—27 ene 2020
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
CVE-2019-19389Media (5.4)0.83%—26 dic 2019
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVE-2019-19703Media (6.1)0.64%—10 dic 2019
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
CVE-2019-12737Media (5.3)0.68%—2 oct 2019
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
CVE-2019-12736Crítica (9.8)2.2%—2 oct 2019
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
CVE-2019-10102Alta (8.1)0.82%—3 jul 2019
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was…

Otros productos de Jetbrains