CVE-2020-7622
06.04.2020, 15:15
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.Enginsight
| Vendor | Product | Version |
|---|---|---|
| jooby | jooby | 𝑥 < 1.6.9 |
| jooby | jooby | 2.0.0 ≤ 𝑥 < 2.2.1 |
𝑥
= Vulnerable software versions
References