Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfc9-2cqg-9wq6

Опубликовано: 09 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.

Пакеты

Наименование

io.projectreactor.netty:reactor-netty

maven
Затронутые версииВерсия исправления

>= 1.3.0, <= 1.3.5

1.3.6

Наименование

io.projectreactor.netty:reactor-netty

maven
Затронутые версииВерсия исправления

>= 1.2.0, <= 1.2.17

1.2.18

Наименование

io.projectreactor.netty:reactor-netty

maven
Затронутые версииВерсия исправления

>= 1.1.0, <= 1.1.31

Отсутствует

Наименование

io.projectreactor.netty:reactor-netty

maven
Затронутые версииВерсия исправления

>= 1.0.0, <= 1.0.48

Отсутствует

EPSS

Процентиль: 7%
0.00172
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
redhat
2 месяца назад

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.

CVSS3: 6.1
nvd
2 месяца назад

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.

EPSS

Процентиль: 7%
0.00172
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-522