Description
Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.
Remediation
References
https://github.com/wocommunity/wonder/pull/992
https://xmit.xyz/security/webobjects-url-tomfoolery/
Related Vulnerabilities
CVE-2022-38180 Vulnerability in maven package io.ktor:ktor-client-core
CVE-2022-42889 Vulnerability in maven package org.apache.commons:commons-text
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http2:http2-hpack
CVE-2022-36031 Vulnerability in npm package directus
CVE-2016-3092 Vulnerability in maven package commons-fileupload:commons-fileupload