Description
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
Remediation
References
https://github.com/oblac/jodd-http/issues/9
https://github.com/oblac/jodd/issues/787
Related Vulnerabilities
CVE-2023-27564 Vulnerability in npm package n8n
CVE-2021-21294 Vulnerability in maven package org.http4s:http4s-blaze-server_2.12
CVE-2019-10759 Vulnerability in npm package safer-eval
CVE-2020-7726 Vulnerability in npm package safe-object2
CVE-2017-16165 Vulnerability in npm package calmquist.static-server