CVE-2021-25761: Weak Encryption
Published Feb 3, 2021
·Updated
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
Affected Software
1 affected component
JetBrains Ktor<1.5.0
Event History
Feb 3, 2021
CVE Published
via MITRE·03:21 PM
Data Sourced
via MITRE·03:21 PM
Description
Frequently Asked Questions
1
What is CVE-2021-25761?
CVE-2021-25761 is a vulnerability in JetBrains Ktor before version 1.5.0 that allowed for a birthday attack on SessionStorage key.
2
What is the severity of CVE-2021-25761?
The severity of CVE-2021-25761 is medium with a severity value of 5.3.
3
How does CVE-2021-25761 affect JetBrains Ktor?
CVE-2021-25761 affects JetBrains Ktor versions prior to 1.5.0 by making a birthday attack on SessionStorage key possible.
4
How can I fix CVE-2021-25761 in JetBrains Ktor?
To fix CVE-2021-25761, it is recommended to update JetBrains Ktor to version 1.5.0 or above.
5
Where can I find more information about CVE-2021-25761?
More information about CVE-2021-25761 can be found in the JetBrains Security Bulletin Q4 2020 on the JetBrains blog.