CVE-2022-29035: Medium severity ktor vulnerability
Published Apr 11, 2022
·Updated
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
Affected Software
1 affected component
JetBrains Ktor<2.0.0
Remediation
Patch Available
Patch Available
Event History
Apr 11, 2022
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-29035.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations'.
3
What is the severity of CVE-2022-29035?
The severity of CVE-2022-29035 is medium with a severity value of 2.7.
4
What software is affected by CVE-2022-29035?
JetBrains Ktor versions up to exclusive 2.0.0 are affected by CVE-2022-29035.
5
How can I fix CVE-2022-29035?
To fix CVE-2022-29035, update JetBrains Ktor to version 2.0.0 or higher.