Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-5404

Опубликовано: 03 мар. 2020
Источник: redhat
CVSS3: 5.9

Описание

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Integration Camel K 1reactor-nettyNot affected
Text-Only RHOARreactor-nettyFixedRHSA-2022:876114.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1975160reactor-netty: specific redirect configuration allows for a credentials leak

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
почти 6 лет назад

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

CVSS3: 5.9
github
почти 4 года назад

Insufficiently Protected Credentials in Reactor Netty

5.9 Medium

CVSS3