Headline
GHSA-hccx-cg4v-hrjx: JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication provider
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication provider
Moderate severity GitHub Reviewed Published Aug 13, 2022 • Updated Aug 30, 2022
Related news
CVE-2022-38180: KTOR-4618 Fix nesting of Authentication providers by rsinukov · Pull Request #3092 · ktorio/ktor
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases