Jooby is a lightweight, modular Java web framework used to build modern applications, and its vulnerability profile centers on its core product with recurring exposure to path-traversal and cross-site scripting weaknesses that are typical of web application input-handling code. Current CVE counts, severity distributions, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jooby over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7622CRITICAL This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header is | Apr 6, 2020 | 9.8 | 24 | NO | NO |
CVE-2019-15477MEDIUM Jooby before 1.6.4 has XSS via the default error handler. | Aug 23, 2019 | 6.1 | 19 | NO | NO |
CVE-2020-7647MEDIUM All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vecto | May 11, 2020 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jooby.
Media articles that mention a CVE ID that affects a product developed by Jooby — matched by CVE ID, not by vendor name.