Описание
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0 (включая) до 6.2.1 (исключая)
cpe:2.3:a:jodd:jodd_http:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00084
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 3 лет назад
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
CVSS3: 7.5
debian
больше 3 лет назад
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vul ...
EPSS
Процентиль: 25%
0.00084
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-74