This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2024-09-16T17:03:41.455Z

Reserved: 2020-01-21T00:00:00

Link: CVE-2020-7622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-06T15:15:12.770

Modified: 2024-11-21T05:37:29.360

Link: CVE-2020-7622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.