Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j52r-xc68-q8f4

Опубликовано: 23 окт. 2019
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Insufficiently Protected Credentials in Pivotal Reactor Netty

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.

Пакеты

Наименование

io.projectreactor.netty:reactor-netty

maven
Затронутые версииВерсия исправления

< 0.8.11

0.8.11

EPSS

Процентиль: 60%
0.00392
Низкий

8.6 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.6
nvd
больше 6 лет назад

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.

EPSS

Процентиль: 60%
0.00392
Низкий

8.6 High

CVSS3

Дефекты

CWE-522