CVE-2021-29480
- EPSS 0.09%
- Veröffentlicht 29.06.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:01:13
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the application startup time as the signing key by default. This means that if an attacker can determine this time, and if encryption ...
CVE-2021-29481
- EPSS 0.07%
- Veröffentlicht 29.06.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:01:13
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions results in unencrypted, but signed, data being set as cookie values. This means that if something sensitive goes into th...
CVE-2021-29485
- EPSS 2.48%
- Veröffentlicht 29.06.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:01:14
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a maliciously crafted Java deserialization gadget chain leveraged against the Ratpack session store. If o...
CVE-2021-29479
- EPSS 0.23%
- Veröffentlicht 29.06.2021 15:15:18
- Zuletzt bearbeitet 21.11.2024 06:01:13
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` header can be used to perform cache poisoning of a cache fronting a Ratpack server if the cache key does not include the `X-Forwarded-H...
CVE-2019-17513
- EPSS 1.25%
- Veröffentlicht 18.10.2019 03:15:09
- Zuletzt bearbeitet 21.11.2024 04:32:25
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, ...
CVE-2019-11808
- EPSS 0.29%
- Veröffentlicht 07.05.2019 07:29:05
- Zuletzt bearbeitet 21.11.2024 04:21:48
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theo...