HTTP Authorization Header Exposure in Ktor Client Software
CVE-2019-19703
6.1MEDIUM
What is CVE-2019-19703?
In Ktor versions up to 1.2.6, an issue exists where the client improperly handles HTTP redirects by resending sensitive data from the HTTP Authorization header to the redirected URL. This behavior could potentially expose user credentials or sensitive authentication tokens to unintended recipients, posing a significant security risk. Affected users should upgrade to the latest version to avoid the vulnerabilities associated with this behavior.