Description
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
Remediation
References
https://github.com/oblac/jodd/issues/787
https://github.com/oblac/jodd-http/issues/9
Related Vulnerabilities
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2020-7760 Vulnerability in maven package org.webjars.bower:codemirror
CVE-2021-45457 Vulnerability in maven package org.apache.kylin:kylin-server
CVE-2021-44878 Vulnerability in maven package org.pac4j:pac4j-core
CVE-2020-7637 Vulnerability in maven package org.webjars.npm:class-transformer