In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
ktor
Vendor: jetbrains
Security Vulnerability Index
Page 1 / 3In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
In JetBrains Ktor before 2.3.5 server certificates were not verified
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations