QID 981639
QID 981639: Java (maven) Security Update for io.projectreactor.netty:reactor-netty (GHSA-j52r-xc68-q8f4)
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j52r-xc68-q8f4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-j52r-xc68-q8f4 -
github.com/advisories/GHSA-j52r-xc68-q8f4
CVEs related to QID 981639
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j52r-xc68-q8f4 | io.projectreactor.netty:reactor-netty |
|