CVE-2019-19703Open Redirect in Ktor

CWE-601Open Redirect4 documents4 sources
Severity
6.1MEDIUMNVD
EPSS
0.0%
top 99.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateFeb 12

Description

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDjetbrains/ktor1.2.6

🔴Vulnerability Details

3
GHSA
URL Redirection to Untrusted Site (Open Redirect) in Ktor2020-02-12
OSV
URL Redirection to Untrusted Site (Open Redirect) in Ktor2020-02-12
CVEList
CVE-2019-19703: In Ktor through 12019-12-10
CVE-2019-19703 — Open Redirect in Jetbrains Ktor | cvebase