All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2024-08-04T22:32:01.587Z

Reserved: 2019-04-03T00:00:00

Link: CVE-2019-10770

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-28T01:15:10.753

Modified: 2024-11-21T04:19:53.293

Link: CVE-2019-10770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.