Low severity3.7NVD Advisory· Published May 7, 2019· Updated Jun 17, 2026
CVE-2019-11808
CVE-2019-11808
Description
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.ratpack:ratpack-sessionMaven | < 1.6.1 | 1.6.1 |
io.ratpack:ratpack-javaMaven | < 1.6.1 | 1.6.1 |
io.ratpack:ratpack-groovyMaven | < 1.6.1 | 1.6.1 |
Affected products
4- Ratpack/Ratpackdescription
- ghsa-coords3 versionspkg:maven/io.ratpack/ratpack-groovypkg:maven/io.ratpack/ratpack-javapkg:maven/io.ratpack/ratpack-session
< 1.6.1+ 2 more
- (no CPE)range: < 1.6.1
- (no CPE)range: < 1.6.1
- (no CPE)range: < 1.6.1
Patches
Vulnerability mechanics
References
5- github.com/ratpack/ratpack/commit/f2b63eb82dd71194319fd3945f5edf29b8f3a42dnvdPatchThird Party AdvisoryWEB
- github.com/ratpack/ratpack/issues/1448nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-54mg-vgrp-mwx9ghsaADVISORY
- github.com/ratpack/ratpack/releases/tag/v1.6.1nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-11808ghsaADVISORY
News mentions
0No linked articles in our index yet.