CVE-2020-7622

Description

This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isnt being abused for HTTP Response Splitting.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.451

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-7622 are fixed in Netty-jooby-netty 2.2.1Windows
Vulnerabilities CVE-2020-7622 are fixed in Netty-jooby-netty for Linux 2.2.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234