VYPR

Maven package

io.ratpack/ratpack-java

pkg:maven/io.ratpack/ratpack-java

Vulnerabilities (1)

  • CVE-2019-11808May 7, 2019
    affected < 1.6.1fixed 1.6.1

    Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequen