Session Storage Vulnerability in JetBrains Ktor
CVE-2021-25761
5.3MEDIUM
What is CVE-2021-25761?
Earlier versions of JetBrains Ktor, prior to 1.5.0, are susceptible to a birthday attack targeting the SessionStorage key. This vulnerability allows an attacker to potentially predict the session key based on specific patterns in session identifiers. As a consequence, attackers may gain unauthorized access to user sessions, leading to serious security implications. Developers using Ktor are advised to upgrade to the latest version to mitigate this risk.