QID 981788
QID 981788: Java (maven) Security Update for io.ratpack:ratpack-groovy (GHSA-54mg-vgrp-mwx9)
Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-54mg-vgrp-mwx9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-54mg-vgrp-mwx9 -
github.com/advisories/GHSA-54mg-vgrp-mwx9
CVEs related to QID 981788
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-54mg-vgrp-mwx9 | io.ratpack:ratpack-groovy |
|
|
| GHSA-54mg-vgrp-mwx9 | io.ratpack:ratpack-java |
|
|
| GHSA-54mg-vgrp-mwx9 | io.ratpack:ratpack-session |
|