CVE-2019-11808

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/05/2019
Last modified:
08/05/2019

Description

Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. This means that if an attacker can determine a small window for the server start time and obtain a session ID value, they can theoretically determine the sequence of session IDs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ratpack_project:ratpack:*:*:*:*:*:*:*:* 1.6.1 (excluding)