threatengine.sh
· ··:··
Sign in
free plan Dashboard My profile Stack Monitoring Notifications Watchlist Account & tokens Community leaderboard API docs Pricing Sign out
Home/Product/ratpack project ratpack
Product

ratpack project ratpack

7 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-29485
< 1.9.0
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execu
9.9CRITICAL
CVE-2021-29481
< 1.9.0
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side sessions
6.5MEDIUM
CVE-2021-29480
< 1.9.0
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the applicatio
4.4MEDIUM
CVE-2021-29479
< 1.9.0
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied X-Forwarded-Host header can be u
7.0HIGH
CVE-2019-10770
>= 0.9.10 and < 1.7.6
All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This
6.1MEDIUM
CVE-2019-17513
< 1.7.5
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no valida
7.5HIGH
CVE-2019-11808
< 1.6.1
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means
3.7LOW
◈SOC and Response
  • CVE triage
  • Stack monitoring
  • Am I affected
  • IOC triage
  • KEV catalog
  • Recently exploited
  • Daily brief
  • Change tracking
◆Detection Engineering
  • Detection coverage workspace
  • Saved stacks
  • SIEM query builder
  • Detection rules
  • D3FEND
◎Threat Hunting
  • Threat actors
  • ATT&CK techniques
  • Attack paths
  • Indicators
  • Ransomware groups
  • Atomic tests
▲Red Team and Pentest
  • Exploitability triage
  • Recon pack
  • Attack paths
  • CAPEC patterns
  • Adversary emulation
■Compliance and GRC
  • Framework mapping
  • Control assessment
  • Audit view
◯About
  • All capabilities
  • Leaderboard
  • Hall of Fame
  • Pricing
  • API docs
  • Integrations
  • Privacy policy
  • Terms of service
threatengine.sh
Are you sure?
We use one first-party cookie to remember how you found us, only if you allow it. Everything the site needs to work uses essential cookies. See our privacy policy.