QID 981810
QID 981810: Java (maven) Security Update for io.jooby:jooby-netty (GHSA-gv3v-92v6-m48j)
Security update has been released for io.jooby:jooby-netty to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
- Cross Site Scripting
- Cache Poisoning
- Page Hijacking
Solution
This was fixed in version `2.2.1`.Workaround:
If you are unable to update, ensure that user supplied data isn't able to flow to HTTP headers. If it does, pre-sanitize for CRLF characters.
If you are unable to update, ensure that user supplied data isn't able to flow to HTTP headers. If it does, pre-sanitize for CRLF characters.
Vendor References
- GHSA-gv3v-92v6-m48j -
github.com/advisories/GHSA-gv3v-92v6-m48j
CVEs related to QID 981810
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gv3v-92v6-m48j | io.jooby:jooby-netty |
|