CVE-2020-5207

In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle n as a headers separator.
References
Configurations

Configuration 1

cpe:2.3:a:jetbrains:ktor:*:*:*:*:*:*:*:*

Information

Published : 2020-01-27 08:15

Updated : 2020-02-04 02:41


NVD link : CVE-2020-5207

Mitre link : CVE-2020-5207

Products Affected
No products.
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')