This affects the package io.jooby:jooby-netty prior to 1.6.9, from 2.0.0 and prior to 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jooby jooby |