Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
Metrics
Affected Vendors & Products
References
History
Fri, 16 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jodd jodd Http
|
|
CPEs | cpe:2.3:a:jodd:jodd_http:*:*:*:*:*:*:*:* | |
Vendors & Products |
Jodd http
|
Jodd jodd Http
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-06-06T20:03:03
Updated: 2024-08-03T06:26:06.555Z
Reserved: 2022-04-25T00:00:00
Link: CVE-2022-29631
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-06-06T21:15:08.697
Modified: 2024-11-21T06:59:27.777
Link: CVE-2022-29631
Redhat
No data.