5
CVSSv2

CVE-2022-29631

Published: 06/06/2022 Updated: 14/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Jodd HTTP v6.0.9 exists to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow malicious users to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jodd http

Vendor Advisories

Debian Bug report logs - #1013270 jodd: CVE-2022-29631 Package: src:jodd; Maintainer for src:jodd is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 20 Jun 2022 13:33:02 UTC Severity: important Tags: security, upstream Forwarded t ...