JoddCVEs & Vulnerabilities
2 CVEs affecting Jodd products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
jodd 1jodd http 1
CVE-2022-29631HIGH
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
7 Jun 2022
7.5
CVSS
CVE-2018-21234CRITICAL
Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
22 May 2020
9.8
CVSS
← PrevPage 1 / 1Next →