CVE-2022-38180: Medium severity ktor vulnerability
Published Aug 12, 2022
·Updated
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
Affected Software
1 affected component
JetBrains Ktor<2.1.0
Event History
Aug 12, 2022
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38180?
CVE-2022-38180 is a vulnerability in JetBrains Ktor before version 2.1.0 where the wrong authentication provider could be selected in some cases.
2
How severe is CVE-2022-38180?
CVE-2022-38180 has a severity score of 6.5 (medium).
3
How does CVE-2022-38180 affect JetBrains Ktor?
CVE-2022-38180 affects JetBrains Ktor before version 2.1.0.
4
How can I fix CVE-2022-38180?
To fix CVE-2022-38180, update JetBrains Ktor to version 2.1.0 or later.
5
Is there any additional information about CVE-2022-38180?
For more information about CVE-2022-38180, you can refer to the following resources: [GitHub Pull Request](https://github.com/ktorio/ktor/pull/3092) and [JetBrains Security Bulletin](https://www.jetbrains.com/privacy-security/issues-fixed/).