First published: Mon Apr 11 2022(Updated: )
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
Credit: security@jetbrains.com
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains Ktor | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-29035.
The title of the vulnerability is 'In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations'.
The severity of CVE-2022-29035 is medium with a severity value of 2.7.
JetBrains Ktor versions up to exclusive 2.0.0 are affected by CVE-2022-29035.
To fix CVE-2022-29035, update JetBrains Ktor to version 2.0.0 or higher.