VendorsRatpack Projectratpackany version
Vulnerabilities

Ratpack Project Ratpack any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-29485
Remote Code Execution Vulnerability in Session Storage
Published 2021-06-29 · Modified
9.9EPSS 0.020
CVE-2019-17513
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.
Published 2019-10-18 · Modified
7.5EPSS 0.022
CVE-2021-29481
Client side sessions should not allow unencrypted storage
Published 2021-06-29 · Modified
7.5EPSS 0.005
CVE-2021-29479
Cached redirect poisoning via X-Forwarded-Host header
Published 2021-06-29 · Modified
7.0EPSS 0.009
CVE-2021-29480
Default client side session signing key is highly predictable
Published 2021-06-29 · Modified
4.4EPSS 0.003
CVE-2019-11808
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.
Published 2019-05-07 · Modified
4.3EPSS 0.013