Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5404

Опубликовано: 03 мар. 2020
Источник: nvd
CVSS3: 6.5
CVSS3: 5.9
CVSS2: 4.9
EPSS Низкий

Описание

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pivotal:reactor_netty:*:*:*:*:*:*:*:*
Версия от 0.8.0 (включая) до 0.8.15 (включая)
cpe:2.3:a:pivotal:reactor_netty:*:*:*:*:*:*:*:*
Версия от 0.9.0 (включая) до 0.9.4 (включая)

EPSS

Процентиль: 45%
0.00228
Низкий

6.5 Medium

CVSS3

5.9 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-522
CWE-522

Связанные уязвимости

CVSS3: 5.9
redhat
почти 6 лет назад

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

CVSS3: 5.9
github
почти 4 года назад

Insufficiently Protected Credentials in Reactor Netty

EPSS

Процентиль: 45%
0.00228
Низкий

6.5 Medium

CVSS3

5.9 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-522
CWE-522