Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown

CVE-2022-29035

Disclosure Date: April 11, 2022 (last updated October 07, 2023)
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
Attacker Value
Unknown

CVE-2022-25204

Disclosure Date: February 15, 2022 (last updated October 25, 2023)
Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.
Attacker Value
Unknown

CVE-2021-43203

Disclosure Date: November 09, 2021 (last updated November 28, 2024)
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
Attacker Value
Unknown

CVE-2021-25763

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
Attacker Value
Unknown

CVE-2021-25762

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
Attacker Value
Unknown

CVE-2021-25761

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
Attacker Value
Unknown

CVE-2020-26129

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
Attacker Value
Unknown

Request smuggling is possible in Ktor when both chunked TE and content length s…

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
Attacker Value
Unknown

CVE-2019-19703

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
Attacker Value
Unknown

CVE-2019-12736

Disclosure Date: October 02, 2019 (last updated November 27, 2024)
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.