Use of Cache Containing Sensitive Information Affecting io.ktor:ktor-client-core package, versions [,3.0.0-rc-2)
Threat Intelligence
EPSS
0.04% (11th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-IOKTOR-8230428
- published 18 Oct 2024
- disclosed 17 Oct 2024
- credit Nils Barlaug
Introduced: 17 Oct 2024
CVE-2024-49580 Open this link in a new tabHow to fix?
Upgrade io.ktor:ktor-client-core
to version 3.0.0-rc-2 or higher.
Overview
io.ktor:ktor-client-core is a framework for quickly creating web applications in Kotlin with minimal effort.
Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information due to improper caching in the HttpCache
plugin. An attacker can disclose sensitive response information by exploiting the misconfigured cache settings.