QID 980974
QID 980974: Java (maven) Security Update for io.ratpack:ratpack-core (GHSA-mvqp-q37c-wf9j)
Security update has been released for io.ratpack:ratpack-core to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
- Cross-User Defacement
- Cache Poisoning
- Cross-Site Scripting
- Page Hijacking
Solution
This vulnerability has been patched in Ratpack version 1.7.5.Workaround:
The workaround for this vulnerability is to either not use arbitrary input as response header values or validate such values before being used to ensure they don't contain a carriage return and/or line feed characters.
The workaround for this vulnerability is to either not use arbitrary input as response header values or validate such values before being used to ensure they don't contain a carriage return and/or line feed characters.
Vendor References
- GHSA-mvqp-q37c-wf9j -
github.com/advisories/GHSA-mvqp-q37c-wf9j
CVEs related to QID 980974
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mvqp-q37c-wf9j | io.ratpack:ratpack-core |
|