Jetbrains
Jetbrains Ktor: vulnerabilidades y CVE
Jetbrains Ktor tiene 22 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses1
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-68762 | Media (5.9) | 0.37% | — | 17 ago 2026 | In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible |
| CVE-2025-29904 | Media (5.3) | 0.32% | — | 12 mar 2025 | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible |
| CVE-2024-49580 | Media (5.3) | 0.35% | — | 17 oct 2024 | In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure |
| CVE-2023-45613 | Crítica (9.1) | 0.30% | — | 9 oct 2023 | In JetBrains Ktor before 2.3.5 server certificates were not verified |
| CVE-2023-45612 | Crítica (9.8) | 0.60% | — | 9 oct 2023 | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE |
| CVE-2023-34339 | Baja (3.3) | 0.21% | — | 1 jun 2023 | In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message |
| CVE-2022-48476 | Alta (7.5) | 0.75% | — | 24 abr 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible |
| CVE-2022-38180 | Media (6.5) | 0.72% | — | 12 ago 2022 | In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases |
| CVE-2022-38179 | Media (6.1) | 0.47% | — | 12 ago 2022 | JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack |
| CVE-2022-29930 | Media (4.9) | 0.88% | — | 12 may 2022 | SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1. |
| CVE-2022-29035 | Baja (2.7) | 0.62% | — | 11 abr 2022 | In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations |
| CVE-2021-43203 | Alta (7.5) | 0.86% | — | 9 nov 2021 | In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly. |
| CVE-2021-25763 | Media (5.3) | 0.54% | — | 3 feb 2021 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. |
| CVE-2021-25762 | Media (5.3) | 0.81% | — | 3 feb 2021 | In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible. |
| CVE-2021-25761 | Media (5.3) | 0.54% | — | 3 feb 2021 | In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. |
| CVE-2020-26129 | Media (6.5) | 0.77% | — | 16 nov 2020 | In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible. |
| CVE-2020-5207 | Alta (7.5) | 0.76% | — | 27 ene 2020 | In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator. |
| CVE-2019-19389 | Media (5.4) | 0.83% | — | 26 dic 2019 | JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. |
| CVE-2019-19703 | Media (6.1) | 0.64% | — | 10 dic 2019 | In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. |
| CVE-2019-12737 | Media (5.3) | 0.68% | — | 2 oct 2019 | UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials. |
| CVE-2019-12736 | Crítica (9.8) | 2.2% | — | 2 oct 2019 | JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection. |
| CVE-2019-10102 | Alta (8.1) | 0.82% | — | 3 jul 2019 | JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was… |