Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-7647 | All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal vi All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors. NVD description · AI analysis pending | 5.3 | 2% |
| — | ||
| CVE-2020-7622 | This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-15477 | Jooby before 1.6.4 has XSS via the default error handler. Jooby before 1.6.4 has XSS via the default error handler. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |