9.8

CVE-2020-7622

Exploit

HTTP Response Splitting

This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JoobyJooby Version < 1.6.9
JoobyJooby Version >= 2.0.0 < 2.2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.56% 0.72
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
report@snyk.io 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/jooby-project/jooby/commit/b66e3342cf95205324023cfdf2cb5811e8a6dcf4
Patch
Third Party Advisory
https://github.com/jooby-project/jooby/security/advisories/GHSA-gv3v-92v6-m48j
Third Party Advisory
Exploit
https://snyk.io/vuln/SNYK-JAVA-IOJOOBY-564249
Patch
Third Party Advisory