Описание
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
A flaw was found in the Reactor Netty HTTP Server, which may log request headers in some cases of invalid HTTP requests. This could allow an attacker to access privileged information when WARN level logging is enabled.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Quarkus | reactor-netty-http | Fix deferred | ||
| Red Hat Fuse 7 | reactor-netty-http | Fix deferred | ||
| Red Hat Integration Camel K 1 | reactor-netty-http | Fix deferred | ||
| Red Hat Integration Camel Quarkus 1 | reactor-netty-http | Fix deferred | ||
| Red Hat JBoss Data Grid 7 | reactor-netty-http | Out of support scope | ||
| Red Hat OpenShift Application Runtimes | reactor-netty-http | Fix deferred | ||
| Red Hat support for Spring Boot | reactor-netty-http | Affected | ||
| Red Hat support for Spring Boot 2.7.13 | reactor-netty-http | Fixed | RHSA-2023:4612 | 16.08.2023 |
| RHINT Camel-Springboot 3.18.3 | reactor-netty-http | Fixed | RHSA-2022:8902 | 08.12.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid HTTP requests where logging at WARN level is enabled.
Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
EPSS
4.3 Medium
CVSS3