This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2020-04-06T14:08:48.593894Z

Updated: 2024-09-16T17:03:41.455Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2020-7622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-04-06T15:15:12.770

Modified: 2021-08-03T15:24:12.983

Link: CVE-2020-7622

cve-icon Redhat

No data.