Vulnerabilities (CVE)

Filtered by vendor Jooby Subscribe
Filtered by product Jooby
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7622 1 Jooby 1 Jooby 2021-08-03 7.5 HIGH 9.8 CRITICAL
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.