Filtered by vendor Jodd
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-29631 | 1 Jodd | 1 Jodd Http | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload. | |||||
CVE-2018-21234 | 2 Apache, Jodd | 2 Hive, Jodd | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. |