Description
All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0274 | All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode. |
Github GHSA |
GHSA-r2wf-q3x4-hrv9 | Default development error handler in Ratpack is vulnerable to HTML content injection (XSS) |
References
| Link | Providers |
|---|---|
| https://snyk.io/vuln/SNYK-JAVA-IORATPACK-534882 |
|
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.587Z
Reserved: 2019-04-03T00:00:00.000Z
Link: CVE-2019-10770
No data.
Status : Modified
Published: 2020-01-28T01:15:10.753
Modified: 2024-11-21T04:19:53.293
Link: CVE-2019-10770
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA