Description
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
Remediation
References
https://github.com/wocommunity/wonder/pull/992
https://xmit.xyz/security/webobjects-url-tomfoolery/
Related Vulnerabilities
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5
CVE-2022-36096 Vulnerability in maven package org.xwiki.platform:xwiki-platform-index-ui
CVE-2023-33695 Vulnerability in maven package cn.hutool:hutool-core
CVE-2017-2601 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-14041 Vulnerability in maven package org.webjars.npm:bootstrap