CVE-2020-7622

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/04/2020
Last modified:
03/08/2021

Description

This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jooby:jooby:*:*:*:*:*:*:*:* 1.6.9 (excluding)
cpe:2.3:a:jooby:jooby:*:*:*:*:*:*:*:* 2.0.0 (including) 2.2.1 (excluding)