Vulnerabilities
Vulnerable Software
Pivotal:  >> Reactor Netty  >> 0.8.9  Security Vulnerabilities
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-11-28
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.
CVSS Score
6.5
EPSS Score
0.005
Published
2020-03-03
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
CVSS Score
6.8
EPSS Score
0.004
Published
2019-10-17


Contact Us

Shodan ® - All rights reserved