CVE Vulnerabilities

CVE-2021-25761

Inadequate Encryption Strength

Published: Feb 03, 2021 | Modified: Aug 08, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Ktor Jetbrains * 1.5.0 (excluding)

Potential Mitigations

References