Spring Reactor Netty
cpe:2.3:a:pivotal:reactor_netty:*:*:*:*:*:*:*
- >= 1.0.0, <= 1.0.48
- >= 1.1.0, <= 1.1.31
- >= 1.2.0, <= 1.2.7
- >= 1.3.0-M1, <= 1.3.0-M4
A vulnerability exists in the Reactor Netty HTTP client, versions 1.0.0 through 1.0.48, 1.1.0 through 1.1.31, 1.2.0 through 1.2.7, and 1.3.0-M1 through 1.3.0-M4, where credentials can be leaked during chained redirects. This issue arises only if the HTTP client is configured to follow redirects.
Exploitation of this vulnerability results in an unintentional leak of authentication credentials.
Users should upgrade to Reactor Netty versions 1.2.8 or 1.3.0-M5, or to the corresponding fixed versions in the 1.0.x or 1.1.x branches. Instructions for obtaining these versions are available on the Spring website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.