Description
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
Remediation
References
https://github.com/ktorio/ktor/security/advisories/GHSA-xrr9-rh8p-433v
https://github.com/ktorio/ktor/pull/1547
Related Vulnerabilities
CVE-2021-21343 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-27644 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-server
CVE-2021-43795 Vulnerability in maven package com.linecorp.armeria:armeria
CVE-2016-5004 Vulnerability in maven package org.apache.xmlrpc:xmlrpc
CVE-2017-7957 Vulnerability in maven package org.sonatype.nexus.xstream:xstream