MEDIUM
All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS)
Published Jan 28, 2020
6.1
MEDIUMCVSS 3.1
EPSS 0.86%
Description
All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.
Affected products
- Vendor n/a Product Io.ratpack:ratpack-Core Defaultn/a
- Version all versions from 0.9.10 inclusive and before 1.7.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Io.ratpack:ratpack-Core | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0274 Advisory
- https://github.com/advisories/GHSA-r2wf-q3x4-hrv9 Advisory
- https://github.com/ratpack/ratpack/commit/a3cbb13be1527874528c3b99fc33517c0297b6d3
- https://github.com/ratpack/ratpack/security/advisories/GHSA-r2wf-q3x4-hrv9
- https://nvd.nist.gov/vuln/detail/CVE-2019-10770
- https://snyk.io/vuln/SNYK-JAVA-IORATPACK-534882 x_refsource_CONFIRMExploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jan 28, 2020
Updated Aug 4, 2024
Reserved Apr 3, 2019
Link CVE-2019-10770
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-0274 GHSA-R2WF-Q3X4-HRV9 Assigner snyk
Published Jan 28, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-0274