CVE-2019-11808
Summary
| CVE | CVE-2019-11808 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-07 07:29:00 UTC |
| Updated | 2019-05-08 16:14:00 UTC |
| Description | Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release v1.6.1 · ratpack/ratpack · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| Use UUID directly for generating session IDs · ratpack/ratpack@f2b63eb · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Use UUID directly for generating session IDs · Issue #1448 · ratpack/ratpack · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981788 Java (maven) Security Update for io.ratpack:ratpack-groovy (GHSA-54mg-vgrp-mwx9)