Ratpack
Ratpack · 7 CVEs
CVE-2021-29485
CRITICAL
Remote Code Execution Vulnerability in Session Storage
Jun 29, 2021
CVE-2021-29481
HIGH
Client side sessions should not allow unencrypted storage
Jun 29, 2021
CVE-2021-29480
MEDIUM
Default client side session signing key is highly predictable
Jun 29, 2021
CVE-2021-29479
HIGH
Cached redirect poisoning via X-Forwarded-Host header
Jun 29, 2021
CVE-2019-10770
MEDIUM
All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (…
Jan 28, 2020
CVE-2019-17513
HIGH
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there i…
Oct 18, 2019
CVE-2019-11808
LOW
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom.…
May 7, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-29485 | Remote Code Execution Vulnerability in Session Storage | CRITICAL | 1.99% | Jun 29, 2021 |
| CVE-2021-29481 | Client side sessions should not allow unencrypted storage | HIGH | 0.46% | Jun 29, 2021 |
| CVE-2021-29480 | Default client side session signing key is highly predictable | MEDIUM | 0.26% | Jun 29, 2021 |
| CVE-2021-29479 | Cached redirect poisoning via X-Forwarded-Host header | HIGH | 0.86% | Jun 29, 2021 |
| CVE-2019-10770 | All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode… | MEDIUM | 0.86% | Jan 28, 2020 |
| CVE-2019-17513 | An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP c… | HIGH | 2.15% | Oct 18, 2019 |
| CVE-2019-11808 | Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can dete… | LOW | 1.31% | May 7, 2019 |
Showing 1 to 7 of 7 CVEs