Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-31684

Опубликовано: 20 окт. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.

A flaw was found in the Reactor Netty HTTP Server, which may log request headers in some cases of invalid HTTP requests. This could allow an attacker to access privileged information when WARN level logging is enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusreactor-netty-httpFix deferred
Red Hat Fuse 7reactor-netty-httpFix deferred
Red Hat Integration Camel K 1reactor-netty-httpFix deferred
Red Hat Integration Camel Quarkus 1reactor-netty-httpFix deferred
Red Hat JBoss Data Grid 7reactor-netty-httpOut of support scope
Red Hat OpenShift Application Runtimesreactor-netty-httpFix deferred
Red Hat support for Spring Bootreactor-netty-httpAffected
Red Hat support for Spring Boot 2.7.13reactor-netty-httpFixedRHSA-2023:461216.08.2023
RHINT Camel-Springboot 3.18.3reactor-netty-httpFixedRHSA-2022:890208.12.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-117
https://bugzilla.redhat.com/show_bug.cgi?id=2141353reactor-netty-http: Log request headers in some cases of invalid HTTP requests

EPSS

Процентиль: 58%
0.00366
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.

CVSS3: 4.3
github
больше 3 лет назад

Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens

EPSS

Процентиль: 58%
0.00366
Низкий

4.3 Medium

CVSS3