The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
2020-03-03T18:15:12.157
2024-11-21T05:34:04.980
Modified
CVSSv3.1: 5.9 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:N
6.8
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal | reactor_netty | ≤ 0.8.15 | Yes |
Application | pivotal | reactor_netty | ≤ 0.9.4 | Yes |