← Back to CVE List
CVE-2020-7622
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt