jooby records
3 published records for vendor jooby.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-7622No exploit | HTTP Response Splittingjooby · jooby | Critical9.8 | — | 1.6% | Apr 6, 2020 |
24Monitor | CVE-2019-15477Proof of concept | Jooby before 1.6.4 has XSS via the default error handler.jooby · jooby · CWE-79 | Medium6.1 | — | 1.0% | Aug 23, 2019 |
21Monitor | CVE-2020-7647No exploit | All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Dijooby · jooby · CWE-22 | Medium5.3 | — | 1.6% | May 11, 2020 |
- CVE-2020-762239Monitor
HTTP Response Splitting
CriticalCVSS 9.8No exploitEPSS 2%jooby · joobyApr 6, 2020
- CVE-2019-1547724Monitor
Jooby before 1.6.4 has XSS via the default error handler.
MediumCVSS 6.1Proof of conceptEPSS 1%jooby · joobyAug 23, 2019
- CVE-2020-764721Monitor
All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Di
MediumCVSS 5.3No exploitEPSS 2%jooby · joobyMay 11, 2020