Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpch-h32j-gx6x

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Insufficiently Protected Credentials in Reactor Netty

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

Пакеты

Наименование

io.projectreactor.netty:reactor-netty-http

maven
Затронутые версииВерсия исправления

>= 0.9.0, < 0.9.5

0.9.5

Наименование

io.projectreactor.netty:reactor-netty-http

maven
Затронутые версииВерсия исправления

>= 0.8.0, < 0.8.16

0.8.16

EPSS

Процентиль: 45%
0.00228
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 5.9
redhat
почти 6 лет назад

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

CVSS3: 5.9
nvd
почти 6 лет назад

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

EPSS

Процентиль: 45%
0.00228
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-522