This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2021-08-02T00:00:00

Updated: 2021-08-02T10:26:21

Reserved: 2020-01-21T00:00:00


Link: CVE-2020-7622

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-06T15:15:12.770

Modified: 2021-08-03T15:24:12.983


Link: CVE-2020-7622

JSON object: View

cve-icon Redhat Information

No data.