CVE-2024-49580Use of Cache Containing Sensitive Information in Ktor

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 99.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 17

Description

In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5jetbrains/ktor< 2.3.13
NVDjetbrains/ktor< 3.0.0

🔴Vulnerability Details

3
CVEList
CVE-2024-49580: In JetBrains Ktor before 22024-10-17
OSV
JetBrains Ktor information disclosure2024-10-17
GHSA
JetBrains Ktor information disclosure2024-10-17
CVE-2024-49580 — Jetbrains Ktor vulnerability | cvebase