CVE-2020-5207: Request smuggling is possible in Ktor when both chunked TE and content length specified
Published Jan 27, 2020
·Updated
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
Affected Software
1 affected component
JetBrains Ktor<1.3.0
Remediation
Patch Available
Event History
Jan 27, 2020
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-5207?
CVE-2020-5207 is a vulnerability in Ktor before version 1.3.0 that allows request smuggling when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
2
What is the severity of CVE-2020-5207?
The severity of CVE-2020-5207 is high, with a severity score of 7.5.
3
Which software is affected by CVE-2020-5207?
The affected software is JetBrains Ktor up to version 1.3.0.
4
How can I fix CVE-2020-5207?
To fix CVE-2020-5207, update your Ktor installation to version 1.3.0 or higher.
5
Where can I find more information about CVE-2020-5207?
You can find more information about CVE-2020-5207 in the security advisory published by JetBrains Ktor: [link].