CVE Database
/

CVE-2019-10770

Back to search

CVE-2019-10770

Published: Jan 28, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.

VendorProductVersions

n/a

io.ratpack:ratpack-core

affected
all versions from 0.9.10 inclusive and before 1.7.6

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now