First published: Wed Feb 03 2021(Updated: )
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Ktor | <1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25763 refers to a vulnerability in JetBrains Ktor before version 1.4.2 where weak cipher suites were enabled by default.
CVE-2021-25763 has a severity score of 5.3, which is classified as medium.
CVE-2021-25763 affects JetBrains Ktor versions before 1.4.2 by enabling weak cipher suites by default.
To fix CVE-2021-25763, update JetBrains Ktor to version 1.4.2 or later, which disables weak cipher suites by default.
You can find more information about CVE-2021-25763 in the JetBrains Security Bulletin Q4 2020 blog post: https://blog.jetbrains.com/blog/2021/02/03/jetbrains-security-bulletin-q4-2020/