Описание
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Affected versions:
Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.
A flaw was found in Reactor Netty HTTP client. In specific scenarios, a remote attacker could exploit this vulnerability when the HTTP client is explicitly configured to follow redirects from a secure endpoint to an insecure one. This could lead to the leakage of sensitive credentials.
Отчет
Red Hat ships reactor-netty as a dependency in Red Hat JBoss Fuse 7 and Red Hat JBoss EAP Expansion Pack (XP). This vulnerability is only exploitable when the Reactor Netty HTTP client is explicitly configured to follow redirects, which is not the default behavior.
Меры по смягчению последствий
Do not configure the Reactor Netty HTTP client to automatically follow redirects, or ensure that redirect following is restricted to same-scheme (HTTPS-to-HTTPS) redirects only.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | reactor-netty | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | reactor-netty | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5.
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
EPSS
6.5 Medium
CVSS3