Medium severity6.1NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026
CVE-2019-10770
CVE-2019-10770
Description
All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.ratpack:ratpack-coreMaven | < 1.7.6 | 1.7.6 |
Affected products
2- io.ratpack/ratpack-coredescription
Patches
Vulnerability mechanics
References
5- snyk.io/vuln/SNYK-JAVA-IORATPACK-534882nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r2wf-q3x4-hrv9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10770ghsaADVISORY
- github.com/ratpack/ratpack/commit/a3cbb13be1527874528c3b99fc33517c0297b6d3ghsaWEB
- github.com/ratpack/ratpack/security/advisories/GHSA-r2wf-q3x4-hrv9ghsaWEB
News mentions
0No linked articles in our index yet.