CVE-2021-29479

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-29479
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29479.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-29479
Aliases
Published
2021-06-29T15:15:18Z
Modified
2024-05-14T08:33:22.477281Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied X-Forwarded-Host header can be used to perform cache poisoning of a cache fronting a Ratpack server if the cache key does not include the X-Forwarded-Host header as a cache key. Users are only vulnerable if they do not configure a custom PublicAddress instance. For versions prior to 1.9.0, by default, Ratpack utilizes an inferring version of PublicAddress which is vulnerable. This can be used to perform redirect cache poisoning where an attacker can force a cached redirect to redirect to their site instead of the intended redirect location. The vulnerability was patched in Ratpack 1.9.0. As a workaround, ensure that ServerConfigBuilder::publicAddress correctly configures the server in production.

References

Affected packages

Git / github.com/ratpack/ratpack

Affected ranges

Type
GIT
Repo
https://github.com/ratpack/ratpack
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.5.2
0.6.1

1.*

1.6.0-rc-1

Other

spring-boot-pr-3

v0.*

v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.13
v0.9.14
v0.9.15
v0.9.16
v0.9.17
v0.9.18
v0.9.19
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

v1.*

v1.0.0
v1.0.0-rc-1
v1.0.0-rc-2
v1.0.0-rc-3
v1.1.0
v1.1.1
v1.2.0
v1.2.0-RC-1
v1.2.0-rc-2
v1.3.0
v1.3.0-rc-1
v1.3.0-rc-2
v1.3.1
v1.3.2
v1.3.3
v1.4.0
v1.4.0-rc-1
v1.4.0-rc-2
v1.4.0-rc-3
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.5.0
v1.5.0-rc-1
v1.5.0-rc-2
v1.5.0-rc-3
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.6.0
v1.6.0-rc-2
v1.6.0-rc-3
v1.6.0-rc-4
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.8.0
v1.8.1
v1.8.2
v1.9.0-rc-1
v1.9.0-rc-2