First published: Thu Dec 26 2019(Updated: )
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Ktor | <1.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19389 is a vulnerability in JetBrains Ktor framework before version 1.2.6 that allows for HTTP Response Splitting.
CVE-2019-19389 has a severity rating of 5.4 (medium).
CVE-2019-19389 affects JetBrains Ktor framework before version 1.2.6.
To fix CVE-2019-19389, update to version 1.2.6 or a later version of JetBrains Ktor framework.
You can find more information about CVE-2019-19389 at the following references: [Link 1](https://gist.github.com/JLLeitschuh/6792947ed57d589b08c1cc8b666c7737), [Link 2](https://github.com/ktorio/ktor/pull/1408), [Link 3](https://twitter.com/JLLeitschuh/status/1210256191110230017?s=20).