Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pp3c-cf6j-m3ff

Опубликовано: 07 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Server-Side Request Forgery in Jodd HTTP

Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

Пакеты

Наименование

org.jodd:jodd-http

maven
Затронутые версииВерсия исправления

>= 5.0.0, < 6.2.1

6.2.1

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-74
CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

CVSS3: 7.5
nvd
больше 3 лет назад

Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

CVSS3: 7.5
debian
больше 3 лет назад

Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vul ...

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-74
CWE-918