VDB
Sign up
CRITICAL9.8

GHSA-gv3v-92v6-m48j

Improper Neutralization of CRLF Sequences in HTTP Headers in Jooby ('HTTP Response Splitting)

Quick fix

GHSA-gv3v-92v6-m48j — io.jooby:jooby-netty: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.2.1</version> for io.jooby:jooby-netty

Details

### Impact

- Cross Site Scripting - Cache Poisoning - Page Hijacking

### Patches

This was fixed in version `2.2.1`.

### Workarounds

If you are unable to update, ensure that user supplied data isn't able to flow to HTTP headers. If it does, pre-sanitize for CRLF characters.

### References

##### [CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')](https://cwe.mitre.org/data/definitions/113.html)

I've been poking at libraries to see if they are vulnerable to HTTP Response Splitting and Jooby is my third case of finding this vulnerability.

### Root Cause

This roots cause back to this line in the Jooby codebase:

https://github.com/jooby-project/jooby/blob/93cfc80aa20c188f71a442ea7a1827da380e1c27/modules/jooby-netty/src/main/java/io/jooby/internal/netty/NettyContext.java#L102

The `DefaultHttpHeaders` takes a parameter `validate` which, when `true` (as it is for the no-arg constructor) validates that the header isn't being abused to do HTTP Response Splitting.

### Reported By

This vulnerability was reported by @JLLeitschuh ([Twitter](https://twitter.com/JLLeitschuh))

### For more information If you have any questions or comments about this advisory: * Open an issue in [jooby-project/jooby](https://github.com/jooby-project/jooby/issues)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.jooby:jooby-netty
Introduced in: 0Fixed in: 2.2.1
Fix# pom.xml: bump <version>2.2.1</version> for io.jooby:jooby-netty

References