VYPR
Low severity3.7NVD Advisory· Published May 7, 2019· Updated Jun 17, 2026

CVE-2019-11808

CVE-2019-11808

Description

Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.ratpack:ratpack-sessionMaven
< 1.6.11.6.1
io.ratpack:ratpack-javaMaven
< 1.6.11.6.1
io.ratpack:ratpack-groovyMaven
< 1.6.11.6.1

Affected products

4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.