Security Flaw in JetBrains Ktor Native Affecting Random Nonce Generation
CVE-2022-29035
3.3LOW
What is CVE-2022-29035?
In Ktor Native prior to version 2.0.0, a vulnerability exists due to the use of non-secure random values for generating nonces. This flaw can lead to predictability in nonce values, potentially allowing attackers to exploit insufficient randomness for replay attacks or other security threats. Users are encouraged to update to the latest version to mitigate this risk. For more details, refer to the official JetBrains security fixes documentation and the relevant GitHub pull request.
Affected Version(s)
Ktor Native 2.0.0