CVE-2022-29631: SSRF
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29631?
CVE-2022-29631 refers to multiple CLRF injection vulnerabilities in Jodd HTTP v6.0.9.
What is the severity of CVE-2022-29631?
CVE-2022-29631 has a severity rating of 7.5, which is considered high.
How can the CLRF injection vulnerabilities in Jodd HTTP v6.0.9 be exploited?
The vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) by using a crafted TCP payload.
Which versions of Jodd HTTP are affected by CVE-2022-29631?
Versions between 5.0 and 6.2.1 of Jodd HTTP are affected by CVE-2022-29631.
Are there any references for CVE-2022-29631?
Yes, you can find more information about CVE-2022-29631 in the GitHub issues: - [https://github.com/oblac/jodd-http/issues/9](https://github.com/oblac/jodd-http/issues/9) - [https://github.com/oblac/jodd/issues/787](https://github.com/oblac/jodd/issues/787)