Releases61
Frequency1 month 2 weeks
Last Release
Stars4.06K
Jodd! Lightweight. Java. Zero dependencies. Use what you like.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

9.8 CRITICAL7.5 HIGH

Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.