CVE Vulnerabilities

CVE-2022-29930

Predictable Exact Value from Previous Values

Published: May 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

Weakness

An exact value or random number can be precisely predicted by observing previous values.

Affected Software

Name Vendor Start Version End Version
Ktor Jetbrains 2.0.0 (including) 2.0.0 (including)

Potential Mitigations

References