Description
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6117 | Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload. |
Github GHSA |
GHSA-pp3c-cf6j-m3ff | Server-Side Request Forgery in Jodd HTTP |
References
History
Fri, 16 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jodd jodd Http
|
|
| CPEs | cpe:2.3:a:jodd:jodd_http:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jodd http
|
Jodd jodd Http
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T06:26:06.555Z
Reserved: 2022-04-25T00:00:00.000Z
Link: CVE-2022-29631
No data.
Status : Modified
Published: 2022-06-06T21:15:08.697
Modified: 2024-11-21T06:59:27.777
Link: CVE-2022-29631
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA