Description
Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0705 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to. |
Github GHSA |
GHSA-j52r-xc68-q8f4 | Insufficiently Protected Credentials in Pivotal Reactor Netty |
References
| Link | Providers |
|---|---|
| https://pivotal.io/security/cve-2019-11284 |
|
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-16T23:36:09.978Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11284
No data.
Status : Modified
Published: 2019-10-17T18:15:12.110
Modified: 2024-11-21T04:20:51.060
Link: CVE-2019-11284
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA