CVE-2020-5404

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
03/03/2020
Last modified:
07/07/2021

Description

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal:reactor_netty:*:*:*:*:*:*:*:* 0.8.0 (including) 0.8.15 (including)
cpe:2.3:a:pivotal:reactor_netty:*:*:*:*:*:*:*:* 0.9.0 (including) 0.9.4 (including)


References to Advisories, Solutions, and Tools