CVE-2021-25763: Medium severity ktor vulnerability
Published Feb 3, 2021
·Updated
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
Affected Software
1 affected component
JetBrains Ktor<1.4.2
Event History
Feb 3, 2021
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
Description
Frequently Asked Questions
1
What is CVE-2021-25763?
CVE-2021-25763 refers to a vulnerability in JetBrains Ktor before version 1.4.2 where weak cipher suites were enabled by default.
2
How severe is CVE-2021-25763?
CVE-2021-25763 has a severity score of 5.3, which is classified as medium.
3
How does CVE-2021-25763 affect JetBrains Ktor?
CVE-2021-25763 affects JetBrains Ktor versions before 1.4.2 by enabling weak cipher suites by default.
4
How can I fix CVE-2021-25763?
To fix CVE-2021-25763, update JetBrains Ktor to version 1.4.2 or later, which disables weak cipher suites by default.
5
Where can I find more information about CVE-2021-25763?
You can find more information about CVE-2021-25763 in the JetBrains Security Bulletin Q4 2020 blog post: https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/