io.ktor:ktor-utils@2.0.3 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the io.ktor:ktor-utils package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Reflect File Download (RFD)

Affected versions of this package are vulnerable to Reflect File Download (RFD) in the io/ktor/http/ContentDisposition and io/ktor/http/HeaderValue classes in ktor-http.api, which fail to encode the Content-Disposition filename parameter, allowing untrusted files to be downloaded.

How to fix Reflect File Download (RFD)?

Upgrade io.ktor:ktor-utils to version 2.1.0 or higher.

[,2.1.0)