Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-hccx-cg4v-hrjx: JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication provider

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

ghsa
#git#auth

JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication provider

Moderate severity GitHub Reviewed Published Aug 13, 2022 • Updated Aug 30, 2022

Related news

CVE-2022-38180: KTOR-4618 Fix nesting of Authentication providers by rsinukov · Pull Request #3092 · ktorio/ktor

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases