Back

MEDIUM

Authentication Leak On Redirect With Reactor Netty HttpClient

Published Mar 3, 2020

Description

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Mar 3, 2020
Updated Sep 17, 2024
Reserved Jan 3, 2020
NVD
Status Modified
Modified Sep 4, 2026
Red Hat
Severity Moderate
Public date Mar 3, 2020
ENISA EUVD
Assigner pivotal
Published Mar 3, 2020
Updated Sep 17, 2024
Exploited since n/a
EUVD-2022-1019 GHSA-GPCH-H32J-GX6X