SB2020040617 - Inconsistent interpretation of HTTP requests in Jooby
Published: April 6, 2020 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2020-7622)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
All versions of Jooby before 2.2.1 are vulnerable to HTTP Response Splitting. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
Remediation
Install update from vendor's website.