Weak Cipher Suites in JetBrains Ktor Affecting Security Configurations
CVE-2021-25763

5.3MEDIUM

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
3 February 2021

Summary

In JetBrains Ktor versions prior to 1.4.2, weak cipher suites were enabled by default, potentially exposing applications to various security risks. This configuration could allow attackers to intercept or tamper with secure communications, highlighting the importance of using strong cipher suites to ensure data integrity and confidentiality.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.