QID 376196

QID 376196: JetBrains Ktor Improper Authentication (KTOR-3091)

Ktor is a web application framework for creating connected systems. You can use it to create server-side as well as client-side applications. It supports multiple platforms, including JVM, JavaScript, and Kotlin/Native.

Affected Versions :
Ktor before 1.6.4

This vulnerability affects an unknown functionality of the component OAuth2 Authentication Handler. The manipulation with an unknown input leads to a weak authentication vulnerability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Update to the latest version of JetBrains Ktor.

    CVEs related to QID 376196

    Software Advisories
    Advisory ID Software Component Link
    KTOR-3091 URL Logo blog.jetbrains.com/blog/2021/11/08/jetbrains-security-bulletin-q3-2021/