In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://github.com/ktorio/ktor/issues/1467 | issue tracking exploit third party advisory |