CVE-2019-19389: Medium severity ktor vulnerability
Published Dec 26, 2019
·Updated
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Affected Software
1 affected component
JetBrains Ktor<1.2.6
Remediation
Patch Available
Event History
Dec 26, 2019
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
Description
Frequently Asked Questions
1
What is CVE-2019-19389?
CVE-2019-19389 is a vulnerability in JetBrains Ktor framework before version 1.2.6 that allows for HTTP Response Splitting.
2
How severe is CVE-2019-19389?
CVE-2019-19389 has a severity rating of 5.4 (medium).
3
How does CVE-2019-19389 affect JetBrains Ktor?
CVE-2019-19389 affects JetBrains Ktor framework before version 1.2.6.
4
How can I fix CVE-2019-19389?
To fix CVE-2019-19389, update to version 1.2.6 or a later version of JetBrains Ktor framework.
5
Where can I find more information about CVE-2019-19389?
You can find more information about CVE-2019-19389 at the following references: [Link 1](https://gist.github.com/JLLeitschuh/6792947ed57d589b08c1cc8b666c7737), [Link 2](https://github.com/ktorio/ktor/pull/1408), [Link 3](https://twitter.com/JLLeitschuh/status/1210256191110230017?s=20).